Patching Unauthenticated File Read Vulnerabilities in At

Secably Research
Oct 07, 2026
7 min read
Vulnerability Research
Arbitrary Cve File Read Unauthenticated
Patching Unauthenticated File Read Vulnerabilities in At
Patching Unauthenticated File Read Vulnerabilities in At

A critical flaw, identified as CVE-2020-1938, allowed for an Unauthenticated Arbitrary File Read in At, specifically Apache Tomcat. This vulnerability, dubbed "Ghostcat," affected Apache Tomcat versions 6.x, 7.x before 7.0.100, 8.x before 8.5.50, and 9.x before 9.0.31. The Common Vulnerability Scoring System (CVSS) v3.0 assigned this vulnerability a base score of 9.8, categorizing it as critical. Attackers could exploit this flaw to read arbitrary files on the system, including sensitive configuration files, application source code, and potentially user data, without requiring any authentication. This compromise could lead to further system access or data exfiltration.

Unauthenticated Arbitrary File Read in At (Apache Tomcat)

CVE-2020-1938, known as Ghostcat, centered on a file inclusion vulnerability within the Apache JServ Protocol (AJP) connector in Apache Tomcat. The AJP protocol facilitates communication between a web server, such as Apache HTTPD or Nginx, and the Tomcat application server. It allows the web server to forward requests to Tomcat for dynamic content processing. The flaw permitted an attacker to include files from arbitrary paths on the server's file system, effectively performing an Unauthenticated Arbitrary File Read in At, specifically targeting Apache Tomcat installations.

The impact of this vulnerability was significant. Successful exploitation allowed attackers to access sensitive files beyond the web root directory. This included files like /WEB-INF/web.xml, which contains application configuration, or even arbitrary files like /etc/passwd on Linux systems. Exposure of such files could reveal credentials, API keys, or other confidential information. This initial compromise often paved the way for further attacks, including remote code execution if specific conditions were met, such as writable web application directories.

Technical Root Cause Analysis

The technical root cause of CVE-2020-1938 lay in the Apache Tomcat AJP connector's improper handling of specific attributes within AJP requests. The AJP protocol uses a binary format for efficient communication. Request attributes, like requestURI and javax.servlet.include.request_uri, are part of this protocol. The vulnerability stemmed from how the AjpProcessor.java component processed these attributes without sufficient validation.

Specifically, the AJP connector, when configured to process requests, could be tricked into treating a crafted request as an internal file inclusion. This misinterpretation occurred because the connector allowed an attacker to manipulate the AJP_FILE and AJP_PATH attributes. These attributes are normally used for internal path resolution within the application. By sending specific values for these attributes, an attacker could bypass normal access controls.

The flaw allowed an attacker to specify a relative path that, when resolved by Tomcat, pointed to any file on the underlying file system. Tomcat's AJP connector would then attempt to serve this file as if it were part of the web application. This direct file access mechanism, combined with the lack of authentication checks for the AJP protocol endpoint, created the Unauthenticated Arbitrary File Read in At vulnerability. The underlying operating system's file permissions still applied, meaning an attacker could only read files accessible by the user running the Tomcat process.

Exploitation Mechanics

Exploiting the Unauthenticated Arbitrary File Read in At vulnerability in Apache Tomcat typically involves sending specially crafted AJP requests directly to the AJP connector port, usually 8009. This attack vector requires the AJP connector to be externally accessible or exposed on the network. Attackers do not need valid credentials to initiate this interaction, making it an unauthenticated attack. The core of the exploit involves manipulating the AJP message structure to include arbitrary file paths.

An attacker constructs an AJP request that includes specific headers, notably setting the AJP_FILE and AJP_PATH attributes. For example, to read the web.xml configuration file from a web application named 'ROOT', an attacker would set the `AJP_FILE` attribute to point to /WEB-INF/web.xml and the `AJP_PATH` attribute to /. The AJP connector processes this request, resolves the path, and returns the content of the specified file. This allows for the direct retrieval of sensitive application files.

Reading system files follows a similar pattern. An attacker could set the `AJP_FILE` attribute to /etc/passwd (on Linux) or C:\Windows\win.ini (on Windows) and the `AJP_PATH` to a non-existent directory to prevent Tomcat from attempting to resolve it as a web application resource. The AJP connector, due to the vulnerability, would then attempt to open and return the content of the specified system file. This technique demonstrates the arbitrary nature of the file read capability, extending beyond the web application's sandbox.


# Example (conceptual, not a runnable exploit code)
# An AJP request would be a binary frame.
# Key attributes manipulated:
# - AJP_REQUEST_TYPE: 0x02 (Forward Request)
# - AJP_METHOD: 0x02 (GET)
# - AJP_PROTOCOL: "HTTP/1.1"
# - AJP_REQUEST_URI: "/"
# - AJP_REMOTE_ADDR: "127.0.0.1"
# - AJP_REMOTE_HOST: "localhost"
# - AJP_SERVER_NAME: "localhost"
# - AJP_SERVER_PORT: 80
# - AJP_IS_SSL: false
# - AJP_ATTRIBUTES:
#   - 0x0A (req_attribute) for "javax.servlet.include.request_uri" with value "/WEB-INF/web.xml"
#   - 0x0A (req_attribute) for "javax.servlet.include.path_info" with value "/"
#   - 0x0A (req_attribute) for "javax.servlet.include.servlet_path" with value "/"

# The actual binary payload construction is complex and involves specific AJP packet formats.

Detection

Detecting the Unauthenticated Arbitrary File Read in At vulnerability in Apache Tomcat involves checking for exposed AJP connectors and monitoring for suspicious activity. The primary indicator of exposure is an open port 8009, which is the default AJP connector port. Network scanning tools like Nmap can quickly identify open ports. A simple command like nmap -p 8009 <target_IP> reveals if the AJP port is accessible.

Organizations can use Secably's free port scanner to identify open ports on their public-facing infrastructure. Inputting the target IP address or domain will scan for common open ports, including 8009. This provides an immediate assessment of AJP connector exposure. If port 8009 is open and accessible from the internet, the system is potentially vulnerable if running an unpatched version of Apache Tomcat.

Beyond port scanning, monitoring server logs for unusual access patterns is crucial. Look for requests to sensitive file paths, such as /WEB-INF/web.xml, ../WEB-INF/web.xml, or common system files like /etc/passwd, that originate from unexpected sources or through the AJP connector. Web application firewalls (WAFs) might log attempts to access these paths, even if they don't explicitly block the AJP protocol.

Internet-wide scanning services, like Zondex, can also help identify publicly exposed AJP services. These platforms actively scan the internet for open ports and banners, providing intelligence on an organization's external attack surface. Regularly checking these services for your assets can reveal unintended exposures.

Remediation Steps

The most critical remediation step for the Unauthenticated Arbitrary File Read in At vulnerability is to immediately upgrade Apache Tomcat to a patched version. The affected versions are 6.x, 7.x before 7.0.100, 8.x before 8.5.50, and 9.x before 9.0.31. Upgrading to Tomcat 7.0.100, 8.5.50, 9.0.31, or later versions directly addresses the flaw by correctly validating AJP request attributes. This update eliminates the path traversal capability that leads to arbitrary file reads.

If an immediate upgrade is not feasible, disable the AJP connector entirely if it is not in use. This prevents any exploitation attempts via the AJP port. To disable the connector, comment out or remove the AJP connector entry in the server.xml configuration file. Look for a section similar to <Connector port="8009" protocol="AJP/1.3" redirectPort="8443" /> and remove or comment it out.

For environments where the AJP connector is necessary, restrict its accessibility. Bind the AJP connector to only listen on localhost (127.0.0.1) or a trusted internal network interface. This ensures only authorized internal systems can communicate over AJP. Configure firewall rules to block external access to port 8009. This significantly reduces the attack surface, preventing unauthenticated external attackers from reaching the vulnerable component.

Furthermore, Apache Tomcat introduced additional security measures in patched versions. Configure the secretRequired attribute to true and define a strong shared secret using the secret attribute for the AJP connector in server.xml. This mandates authentication for AJP requests. Also, consider setting the allowedRequestAttributesPattern to restrict which attributes are processed, further hardening the connector against manipulation.


# Example server.xml configuration for AJP connector hardening:

<!-- Define an AJP 1.3 Connector on port 8009 -->
<Connector port="8009" protocol="AJP/1.3" redirectPort="8443"
           address="127.0.0.1" /> <!-- Bind to localhost -->
           secretRequired="true" secret="YOUR_STRONG_SECRET_HERE"
           allowedRequestAttributesPattern=".*" /> <!-- Or a more restrictive pattern -->

Timeline of Disclosure

The Unauthenticated Arbitrary File Read in At vulnerability, identified as CVE-2020-1938, was discovered by researchers at Chaitin Security Research Lab (now part of Baidu Security). They publicly disclosed their findings, detailing the Ghostcat vulnerability. This discovery highlighted a significant security flaw in the widely used Apache Tomcat server.

The vulnerability was reported to the Apache Tomcat security team in January 2020. This allowed the project developers to develop and release patches before widespread public knowledge of the exploit. Responsible disclosure practices ensured that users had a chance to update their systems.

Apache Tomcat released official patches for affected versions on February 20, 2020. These patches, included in versions 7.0.100, 8.5.50, and 9.0.31, addressed the AJP connector flaw. The public advisory for CVE-2020-1938 was also released around this time, informing users about the vulnerability and the available fixes. This swift action helped mitigate the potential for widespread exploitation.

Check your site for vulnerabilities

Run a free security scan — no signup, results in seconds.

Related Posts

Stronger security starts with visibility.

Scan your website for vulnerabilities and get actionable insights.