CVE-2020-1938
Ghostcat: Apache Tomcat AJP request injection and potential remote code execution
Technology
Apache Tomcat
CVSS Score
9.8 / 10.0
Affected Versions
9.0.0.M1 to 9.0.30; 8.5.0 to 8.5.50; 7.0.0 to 7.0.99
Upstream Fix
9.0.31; 8.5.51; 7.0.100
Published
February 24, 2020
OSSeva Coverage
Fixed upstream
Description
Ghostcat. Tomcat treats AJP connections as more trusted than HTTP connections, and the affected versions shipped with an AJP connector enabled by default on all configured IP addresses. An attacker who could reach the AJP port could return arbitrary files from anywhere in the web application, including WEB-INF and META-INF, and have any file processed as a JSP; with file upload into the web application, that became remote code execution. Fixed in 9.0.31, 8.5.51 and 7.0.100, which also hardened the default AJP connector configuration. Mitigation: remove the AJP connector if unused, or bind it to a trusted address and set a secret. CISA added it to its Known Exploited Vulnerabilities catalog on 3 March 2022.
Is your Apache Tomcat deployment affected?
If you're running 9.0.0.M1 to 9.0.30; 8.5.0 to 8.5.50; 7.0.0 to 7.0.99, you need this patch. Book a discovery call to get covered.