Junglewise Threat Intelligence

CVE-2009-3555: Apache Tomcat plaintext injection via TLS renegotiation

CVE-2009-3555 · Severity: critical · CVSS 9.8 · Published 2022-05-02

Technologies: Apache Tomcat. Vendors: Apache.

Executive brief

Apache Tomcat is a widely used web server and application container for Java-based websites. A vulnerability in the way it handles secure (HTTPS) connections could allow an attacker to intercept and inject data into a user's session. This could lead to the theft of sensitive information or unauthorized actions being performed on behalf of a user.

Technical details

The vulnerability, known as the 'Project Mogul' issue, stems from the TLS and SSL 3.0 protocols failing to properly associate renegotiation handshakes with existing connections. In Apache Tomcat, this allows a man-in-the-middle (MitM) attacker to perform a plaintext injection attack by sending an unauthenticated request that the server retroactively processes in a post-renegotiation context. This can be exploited to insert data into HTTPS sessions or other TLS-protected traffic. The issue was addressed in Tomcat by introducing workarounds that restrict or properly manage renegotiation. Patches are available in versions 7.0.10, 6.0.32, and 5.5.33.

Affected products

  • Apache Tomcat >= 7.0.0, < 7.0.10
  • Apache Tomcat >= 6.0.0, < 6.0.32
  • Apache Tomcat >= 5.0.0, < 5.5.33

Timeline

  • 2022-05-02: advisory: GitHub Advisory published

References

Related threats