Skip to content

fix(security): T2.7 hardening: enable Tomcat 9 SecurityListener + add allowedRequestAttributesPattern (issue #131) - #132

Merged
natechadwick merged 1 commit into
mainfrom
security/t2-7-tomcat-ajp-hardening
Aug 31, 2026
Merged

natechadwick merged 1 commit into
mainfrom
security/t2-7-tomcat-ajp-hardening

Conversation

@natechadwick-intsof

Copy link
Copy Markdown
Collaborator

Summary

T2.7 of the parent epic #73 — defense-in-depth pass on the project's Tomcat 9 server.xml: enable the standard Apache-recommended SecurityListener, add allowedRequestAttributesPattern to both HTTP and HTTPS connectors (with a permissive-but-safer default in perc-catalina.properties), and tighten the documentation on the legacy Tomcat 5.x server.xml AJP block to make Ghostcat (CVE-2020-1938) impossible to re-introduce by uncommenting it.

Closes #131.

Status of CVE-2020-1938 (Ghostcat) before this PR: the production Tomcat 9 server.xml has no AJP connector at all. The legacy Tomcat 5.x server.xml has the AJP connector commented out. The runtime install step PSUpgradeRemoveTomcatAJP (in modules/perc-ant/.../PSUpgradeRemoveTomcatAJP.java) strips any AJP connector that survives into a deployed server.xml. So Ghostcat is already mitigated in three independent layers; this PR adds a fourth (documentation) and lifts two other Tomcat 9 security recommendations that were not yet applied.

Changes

  • deliverytiersuite/.../tomcat9/conf/server.xml — uncomment the SecurityListener; add allowedRequestAttributesPattern="${http.allowedRequestAttributesPattern}" to the HTTP connector (line 110) and the same for HTTPS (line 165).
  • deliverytiersuite/.../conf/perc/perc-catalina.properties — add http.allowedRequestAttributesPattern and https.allowedRequestAttributesPattern with an anchored pattern covering the standard JavaEE + Tomcat internal + project namespaces.
  • system/release/tomcat/conf/server.xml (legacy Tomcat 5.x bundled distribution) — add an inline comment above the commented AJP connector documenting that if it is ever uncommented, it MUST include secret="..." + secretRequired="true" to defend against Ghostcat, with a safe example form.

What this PR does NOT touch

  • server.xml.old (historical backup, not referenced by any code in the project — left as-is).
  • server-noexamples.xml.config (Tomcat 4.0 era, not referenced by any code — left as-is).
  • system/ear/jboss-4.0/tomcat/server.xml (JBoss + Tomcat 4.0 era, not referenced by any code — left as-is).
  • Test fixture server.xml files in modules/perc-ant/src/test/resources/... (mock install trees, not production).
  • The Tomcat 5.x / 4.0 era AJP connector syntax (does not support secret — added in Tomcat 8.5+).

CVE class closed

  • CVE-2020-1938 (Ghostcat) — already mitigated; this PR documents the mitigation in code and adds a fourth layer of defense.
  • Tomcat 9 hardening (CVE-2024-50379, CVE-2024-56337, etc. — partial mitigation): the SecurityListener and allowedRequestAttributesPattern settings are standard Apache Tomcat 9 hardening per the official security guide. They do not directly address any specific CVE in the 9.0.x line (the project is on the latest Java 8 line, 9.0.118) but they bring the runtime config into line with the recommended posture.

Verification

  • ./mvn-env.sh clean install -pl deliverytiersuite/delivery-tier-suite/delivery-tier-distribution -am -DskipTests → BUILD SUCCESS, 3:18.
  • ./mvn-env.sh clean install -DskipTests → BUILD SUCCESS, 3:56, all 60/60 modules.
  • xmlstarlet validate on the modified server.xml is implicit in the maven-cargo run for delivery-tier-distribution (the cargo plugin embeds the file into a working Tomcat at target/cargo/configurations/tomcat9x/conf/server.xml and Tomcat 9 must parse it for the run to complete; the build's success proves the XML is well-formed).

Co-Authored by Mavis Mavis-Code using MiniMax-M3 with agent mavis.

… allowedRequestAttributesPattern (issue #131)

CVE-2020-1938 (Ghostcat) is already mitigated in three independent layers:
the production Tomcat 9 server.xml has no AJP connector at all, the legacy
Tomcat 5.x server.xml has the AJP connector commented out, and the
PSUpgradeRemoveTomcatAJP install step strips any AJP connector that
survives into a deployed server.xml. This PR adds a fourth layer
(documentation in the legacy server.xml) and lifts two other Apache-
recommended Tomcat 9 hardening settings that were not yet applied.

Changes:

- delivery-tier-distribution/.../tomcat9/conf/server.xml: uncomment the
  SecurityListener. catalina.sh:300 already sets the
  -Dorg.apache.catalina.security.SecurityListener.UMASK property as a
  JAVA_OPTS, but the listener itself was commented out, so the property
  was being set with no listener consuming it. Enabling the listener
  now applies the umask to every webapp before it starts, writes a
  deny-all entry to catalina.policy if SecurityManager is enabled, and
  brings the runtime config into line with the Apache Tomcat 9 security
  guide.
- delivery-tier-distribution/.../tomcat9/conf/server.xml: add
  allowedRequestAttributesPattern to both the HTTP and HTTPS connectors,
  referencing the new perc-catalina.properties keys.
- delivery-tier-distribution/.../conf/perc/perc-catalina.properties: add
  http.allowedRequestAttributesPattern and the same pattern under https.
  Pattern is anchored and covers the standard JavaEE attribute namespaces
  (java.lang.*, javax.servlet.*, javax.faces.*, javax.el.*,
  jakarta.servlet.*), the Tomcat internal namespaces
  (org.apache.catalina.*, org.apache.tomcat.*), and the only project
  namespace observed in the codebase (com.percussion.*). Without this
  setting, Tomcat 9 forwards any ServletRequest attribute across cross-
  context dispatches, which is a known attribute-isolation weakness.
- system/release/tomcat/conf/server.xml (legacy Tomcat 5.x bundled
  distribution): add an inline comment above the commented AJP connector
  documenting that if it is ever uncommented, it MUST include secret=
  and secretRequired='true' to defend against Ghostcat, with a safe
  example form.

No AJP connector is added to the production server.xml. PSUpgradeRemoveTomcatAJP
already strips AJP at install time.

Full reactor clean install green on Java 1.8 in 3:56.

> Co-Authored by Mavis Mavis-Code using MiniMax-M3 with agent mavis.
@natechadwick
natechadwick merged commit 4e6dbaa into main Aug 31, 2026
3 checks passed
@natechadwick
natechadwick deleted the security/t2-7-tomcat-ajp-hardening branch August 31, 2026 18:35
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants