Executive brief
Apache Tomcat is a widely used web server and application container for Java-based websites. A vulnerability in the way it handles secure (HTTPS) connections could allow an attacker to intercept and inject data into a user's session. This could lead to the theft of sensitive information or unauthorized actions being performed on behalf of a user.
Technical details
The vulnerability, known as the 'Project Mogul' issue, stems from the TLS and SSL 3.0 protocols failing to properly associate renegotiation handshakes with existing connections. In Apache Tomcat, this allows a man-in-the-middle (MitM) attacker to perform a plaintext injection attack by sending an unauthenticated request that the server retroactively processes in a post-renegotiation context. This can be exploited to insert data into HTTPS sessions or other TLS-protected traffic. The issue was addressed in Tomcat by introducing workarounds that restrict or properly manage renegotiation. Patches are available in versions 7.0.10, 6.0.32, and 5.5.33.
Affected products
- Apache Tomcat >= 7.0.0, < 7.0.10
- Apache Tomcat >= 6.0.0, < 6.0.32
- Apache Tomcat >= 5.0.0, < 5.5.33
Timeline
- 2022-05-02: advisory: GitHub Advisory published