CVE Published: 01/08/2018 |
CVE Updated: 21/10/2024 |
CVE Year: 2018 Source: apache |
Vendor: Apache Software Foundation |
Product: Apache Tomcat Status : PUBLISHED
CVE-2018-8034 Description
The host name verification when using TLS with the WebSocket client was missing. It is now enabled by default. Versions Affected: Apache Tomcat 9.0.0.M1 to 9.0.9, 8.5.0 to 8.5.31, 8.0.0.RC1 to 8.0.52, and 7.0.35 to 7.0.88.