Back to Vulnerability Directory
CRITICALFixed upstream

CVE-2020-1938

Ghostcat: Apache Tomcat AJP request injection and potential remote code execution

Technology

Apache Tomcat

CVSS Score

9.8 / 10.0

Affected Versions

9.0.0.M1 to 9.0.30; 8.5.0 to 8.5.50; 7.0.0 to 7.0.99

Upstream Fix

9.0.31; 8.5.51; 7.0.100

Published

February 24, 2020

OSSeva Coverage

Fixed upstream

Description

Ghostcat. Tomcat treats AJP connections as more trusted than HTTP connections, and the affected versions shipped with an AJP connector enabled by default on all configured IP addresses. An attacker who could reach the AJP port could return arbitrary files from anywhere in the web application, including WEB-INF and META-INF, and have any file processed as a JSP; with file upload into the web application, that became remote code execution. Fixed in 9.0.31, 8.5.51 and 7.0.100, which also hardened the default AJP connector configuration. Mitigation: remove the AJP connector if unused, or bind it to a trusted address and set a secret. CISA added it to its Known Exploited Vulnerabilities catalog on 3 March 2022.

Upstream record: NVD · CVE.org

Is your Apache Tomcat deployment affected?

If you're running 9.0.0.M1 to 9.0.30; 8.5.0 to 8.5.50; 7.0.0 to 7.0.99, you need this patch. Book a discovery call to get covered.