Repository navigation
fix(security): T2.7 hardening: enable Tomcat 9 SecurityListener + add allowedRequestAttributesPattern (issue #131) - #132
Merged
Conversation
… allowedRequestAttributesPattern (issue #131) CVE-2020-1938 (Ghostcat) is already mitigated in three independent layers: the production Tomcat 9 server.xml has no AJP connector at all, the legacy Tomcat 5.x server.xml has the AJP connector commented out, and the PSUpgradeRemoveTomcatAJP install step strips any AJP connector that survives into a deployed server.xml. This PR adds a fourth layer (documentation in the legacy server.xml) and lifts two other Apache- recommended Tomcat 9 hardening settings that were not yet applied. Changes: - delivery-tier-distribution/.../tomcat9/conf/server.xml: uncomment the SecurityListener. catalina.sh:300 already sets the -Dorg.apache.catalina.security.SecurityListener.UMASK property as a JAVA_OPTS, but the listener itself was commented out, so the property was being set with no listener consuming it. Enabling the listener now applies the umask to every webapp before it starts, writes a deny-all entry to catalina.policy if SecurityManager is enabled, and brings the runtime config into line with the Apache Tomcat 9 security guide. - delivery-tier-distribution/.../tomcat9/conf/server.xml: add allowedRequestAttributesPattern to both the HTTP and HTTPS connectors, referencing the new perc-catalina.properties keys. - delivery-tier-distribution/.../conf/perc/perc-catalina.properties: add http.allowedRequestAttributesPattern and the same pattern under https. Pattern is anchored and covers the standard JavaEE attribute namespaces (java.lang.*, javax.servlet.*, javax.faces.*, javax.el.*, jakarta.servlet.*), the Tomcat internal namespaces (org.apache.catalina.*, org.apache.tomcat.*), and the only project namespace observed in the codebase (com.percussion.*). Without this setting, Tomcat 9 forwards any ServletRequest attribute across cross- context dispatches, which is a known attribute-isolation weakness. - system/release/tomcat/conf/server.xml (legacy Tomcat 5.x bundled distribution): add an inline comment above the commented AJP connector documenting that if it is ever uncommented, it MUST include secret= and secretRequired='true' to defend against Ghostcat, with a safe example form. No AJP connector is added to the production server.xml. PSUpgradeRemoveTomcatAJP already strips AJP at install time. Full reactor clean install green on Java 1.8 in 3:56. > Co-Authored by Mavis Mavis-Code using MiniMax-M3 with agent mavis.
4 tasks done
natechadwick
approved these changes
Aug 31, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
T2.7 of the parent epic #73 — defense-in-depth pass on the project's Tomcat 9
server.xml: enable the standard Apache-recommendedSecurityListener, addallowedRequestAttributesPatternto both HTTP and HTTPS connectors (with a permissive-but-safer default inperc-catalina.properties), and tighten the documentation on the legacy Tomcat 5.xserver.xmlAJP block to make Ghostcat (CVE-2020-1938) impossible to re-introduce by uncommenting it.Closes #131.
Status of CVE-2020-1938 (Ghostcat) before this PR: the production Tomcat 9
server.xmlhas no AJP connector at all. The legacy Tomcat 5.xserver.xmlhas the AJP connector commented out. The runtime install stepPSUpgradeRemoveTomcatAJP(inmodules/perc-ant/.../PSUpgradeRemoveTomcatAJP.java) strips any AJP connector that survives into a deployedserver.xml. So Ghostcat is already mitigated in three independent layers; this PR adds a fourth (documentation) and lifts two other Tomcat 9 security recommendations that were not yet applied.Changes
deliverytiersuite/.../tomcat9/conf/server.xml— uncomment theSecurityListener; addallowedRequestAttributesPattern="${http.allowedRequestAttributesPattern}"to the HTTP connector (line 110) and the same for HTTPS (line 165).deliverytiersuite/.../conf/perc/perc-catalina.properties— addhttp.allowedRequestAttributesPatternandhttps.allowedRequestAttributesPatternwith an anchored pattern covering the standard JavaEE + Tomcat internal + project namespaces.system/release/tomcat/conf/server.xml(legacy Tomcat 5.x bundled distribution) — add an inline comment above the commented AJP connector documenting that if it is ever uncommented, it MUST includesecret="..."+secretRequired="true"to defend against Ghostcat, with a safe example form.What this PR does NOT touch
server.xml.old(historical backup, not referenced by any code in the project — left as-is).server-noexamples.xml.config(Tomcat 4.0 era, not referenced by any code — left as-is).system/ear/jboss-4.0/tomcat/server.xml(JBoss + Tomcat 4.0 era, not referenced by any code — left as-is).server.xmlfiles inmodules/perc-ant/src/test/resources/...(mock install trees, not production).secret— added in Tomcat 8.5+).CVE class closed
SecurityListenerandallowedRequestAttributesPatternsettings are standard Apache Tomcat 9 hardening per the official security guide. They do not directly address any specific CVE in the 9.0.x line (the project is on the latest Java 8 line, 9.0.118) but they bring the runtime config into line with the recommended posture.Verification
./mvn-env.sh clean install -pl deliverytiersuite/delivery-tier-suite/delivery-tier-distribution -am -DskipTests→ BUILD SUCCESS, 3:18../mvn-env.sh clean install -DskipTests→ BUILD SUCCESS, 3:56, all 60/60 modules.xmlstarlet validateon the modifiedserver.xmlis implicit in the maven-cargo run fordelivery-tier-distribution(the cargo plugin embeds the file into a working Tomcat attarget/cargo/configurations/tomcat9x/conf/server.xmland Tomcat 9 must parse it for the run to complete; the build's success proves the XML is well-formed).