When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomcat treats AJP connections as having higher trust than, for example, a similar HTTP connection. If such connections are available to an attacker, they can be exploited in ways that may be surprising. In Apache Tomcat 9.0.0.M1 to 9.0.0.30, 8.5.0 to 8.5.50 and 7.0.0 to 7.0.99, Tomcat shipped with an AJP Connector enabled by default that listened on all configured IP addresses. It was expected (and recommended in the security guide) that this Connector would be disabled if not required. This vulnerability report identified a mechanism that allowed: - returning arbitrary files from anywhere in the web application - processing any file in the web application as a JSP Further, if the web application allowed file upload and stored those files within the web application (or the attacker was able to control the content of the web application by some other means) then this, along with the ability to process a file as a JSP, made remote code execution possible. It is important to note that mitigation is only required if an AJP port is accessible to untrusted users. Users wishing to take a defence-in-depth approach and block the vector that permits returning arbitrary files and execution as JSP may upgrade to Apache Tomcat 9.0.31, 8.5.51 or 7.0.100 or later. A number of changes were made to the default AJP Connector configuration in 9.0.31 to harden the default configuration. It is likely that users upgrading to 9.0.31, 8.5.51 or 7.0.100 or later will need to make small changes to their configurations.
CVE-2020-1938
Score elevated to 9.8 because this CVE is listed on the CISA Known Exploited Vulnerabilities catalog (added 2022-03-03), indicating real-world exploitation has been confirmed by US federal agencies. NVD baseline CVSS 9.8 retained for reference. Confidence: HIGH.
- 186 internet-exposed hosts are running an affected version right now
- Actively exploited in the wild (CISA-KEV)
A fix is available — apply it.
186 internet-exposed hosts are running an affected version of CVE-2020-1938 right now.
EchelonGraph is the only CVE feed that fuses live vulnerability intelligence with its own live internet-exposure radar — so you see not just that a CVE is exploited, but how much of the internet is exposed to it right now.
- CVSS v3
- 9.8
- EG Score
- 9.8(high)
- EG Risk
- 99(Act)EG Risk 99/100SSVC: Act
EG Risk is EchelonGraph's 0–100 priority score: it fuses intrinsic severity with real-world exploitation and automatability so you can rank equal-severity CVEs and fix the most dangerous first. Higher = act sooner. Distinct from the 0–10 EG Score (severity).
How it’s computedSeverity98% × 45%Exploitation100% × 40%Automatability100% × 15%Action: Fix now — active exploitation, automatable, high impact. - EPSS
- 99.9%
- KEV
- ⚠ Exploited
Published
February 24, 2020
Last Modified
October 27, 2025
Advisory Details (8)
Auto-updated Jun 1, 2026BlackBerry Public Knowledge Base
http://support.blackberry.com/kb/articleDetail?articleNumber=000062739Vendor Advisories for CVE-2020-1938(2)
These vendors published their own advisory mentioning this CVE — often with vendor-specific remediation steps + affected product lists not in NVD.
Patch Availability(13)
| Vendor / Ecosystem | Fixed in / Patch | Released | Source |
|---|---|---|---|
| redhat | tomcat | 2021-08-11 | redhat |
| redhat | pki-deps:10.6-8030020200527165326.30b713e6 | 2020-11-04 | redhat |
| redhat | tomcat-0:7.0.76-10.el7_6 | 2020-07-07 | redhat |
| redhat | weld-core-0:1.1.34-2.Final_redhat_2.1.ep6.el6 | 2020-07-01 | redhat |
| redhat | weld-core-0:1.1.34-2.Final_redhat_2.1.ep6.el5 | 2020-07-01 | redhat |
| redhat | jbossweb | 2020-07-01 | redhat |
| redhat | weld-core-0:1.1.34-2.Final_redhat_2.1.ep6.el7 | 2020-07-01 | redhat |
| redhat | jws5-tomcat-native-0:1.2.23-4.redhat_4.el8jws | 2020-04-21 | redhat |
| redhat | ajp | 2020-04-21 | redhat |
| redhat | jbossweb-0:7.5.30-2.Final_redhat_2.1.ep6.el7 | 2020-04-14 | redhat |
| redhat | tomcat6-0:6.0.24-114.el6_10 | 2020-03-23 | redhat |
| redhat | tomcat-native-0:1.2.23-21.redhat_21.ep7.el7 | 2020-03-17 | redhat |
| redhat | tomcat-0:7.0.76-11.el7_7 | 2020-03-17 | redhat |
Patches are aggregated from vendor advisories (Red Hat, Microsoft, Cisco, GitHub) and package ecosystems (OSV, GHSA). Multiple rows for the same upstream release have been deduplicated.
Affected Packages
(1 across 1 ecosystem)
Maven(1)
| Package | Vulnerable range | Fixed in | Dependents |
|---|---|---|---|
| org.apache.tomcat.embed:tomcat-embed-core | 7.0.0 ... 7.0.99 (68 versions) | 7.0.100 | — |
Additional Vendor Advisories
(14)
Vendors that published advisories for this CVE beyond the curated set above. Broader coverage but minimal per-row detail — click through for the original advisory.
- Red HatRHSA-2020:0855IMPORTANT2020-02-20
RHSA-2020:0855 — Important
- Red HatRHSA-2020:0860IMPORTANT2020-02-20
RHSA-2020:0860 — Important
- Red HatRHSA-2020:0861IMPORTANT2020-02-20
RHSA-2020:0861 — Important
- Red HatRHSA-2020:0912IMPORTANT2020-02-20
RHSA-2020:0912 — Important
- Red HatRHSA-2020:1478IMPORTANT2020-02-20
RHSA-2020:1478 — Important
- Red HatRHSA-2020:1479IMPORTANT2020-02-20
RHSA-2020:1479 — Important
- Red HatRHSA-2020:1520IMPORTANT2020-02-20
RHSA-2020:1520 — Important
- Red HatRHSA-2020:1521IMPORTANT2020-02-20
RHSA-2020:1521 — Important
- Red HatRHSA-2020:2779IMPORTANT2020-02-20
RHSA-2020:2779 — Important
- Red HatRHSA-2020:2780IMPORTANT2020-02-20
RHSA-2020:2780 — Important
- Red HatRHSA-2020:2781IMPORTANT2020-02-20
RHSA-2020:2781 — Important
- Red HatRHSA-2020:2783IMPORTANT2020-02-20
RHSA-2020:2783 — Important
- Red HatRHSA-2020:2840IMPORTANT2020-02-20
RHSA-2020:2840 — Important
- Red HatRHSA-2021:3140IMPORTANT2020-02-20
RHSA-2021:3140 — Important
Data Freshness Timeline
(refreshed 45× in last 7d / 193× in last 30d)
Each row is a source pipeline that fetched or updated this CVE on that date, with what changed. For example, "NVD update" means NVD published or revised its analysis for this CVE; "MITRE cvelistV5" means we ingested or refreshed it from the CNA feed. Most recent first.
Showing the most recent 100 of 341 total refreshes for this CVE.
- 2026-07-23 01:50 UTCEG score recompute
- 2026-07-22 22:27 UTCEG score recompute
- 2026-07-22 22:27 UTCVendor advisory
- 2026-07-22 19:40 UTCCISA KEV update
- 2026-07-22 18:15 UTCVendor advisory
- 2026-07-22 14:04 UTCVendor advisory
- 2026-07-22 09:54 UTCVendor advisory
- 2026-07-22 05:44 UTCVendor advisory
- 2026-07-22 01:33 UTCVendor advisory
- 2026-07-21 21:22 UTCVendor advisory
- 2026-07-21 17:09 UTCVendor advisory
- 2026-07-21 14:37 UTCCISA KEV update
- 2026-07-21 12:58 UTCVendor advisory
- 2026-07-21 08:48 UTCVendor advisory
- 2026-07-21 04:38 UTCVendor advisory
- 2026-07-21 00:27 UTCVendor advisory
- 2026-07-20 20:17 UTCVendor advisory
- 2026-07-20 16:05 UTCVendor advisory
- 2026-07-20 11:55 UTCVendor advisory
- 2026-07-20 07:45 UTCVendor advisory
- 2026-07-20 03:33 UTCVendor advisory
- 2026-07-19 23:22 UTCVendor advisory
- 2026-07-19 19:11 UTCVendor advisory
- 2026-07-19 15:01 UTCVendor advisory
- 2026-07-19 10:51 UTCVendor advisory
Show 75 moreShow fewer
- 2026-07-19 06:40 UTCVendor advisory
- 2026-07-19 02:30 UTCVendor advisory
- 2026-07-18 22:19 UTCVendor advisory
- 2026-07-18 18:07 UTCVendor advisory
- 2026-07-18 13:57 UTCVendor advisory
- 2026-07-18 09:46 UTCVendor advisory
- 2026-07-18 05:34 UTCVendor advisory
- 2026-07-18 01:24 UTCVendor advisory
- 2026-07-17 21:14 UTCVendor advisory
- 2026-07-17 17:04 UTCVendor advisory
- 2026-07-17 12:51 UTCVendor advisory
- 2026-07-17 08:40 UTCEG score recompute
- 2026-07-17 08:40 UTCVendor advisory
- 2026-07-17 04:30 UTCVendor advisory
- 2026-07-17 00:18 UTCVendor advisory
- 2026-07-16 20:07 UTCVendor advisory
- 2026-07-16 17:04 UTCCISA KEV update
- 2026-07-16 15:57 UTCVendor advisory
- 2026-07-16 11:45 UTCVendor advisory
- 2026-07-16 07:35 UTCVendor advisory
- 2026-07-16 03:24 UTCVendor advisory
- 2026-07-15 23:13 UTCVendor advisory
- 2026-07-15 19:02 UTCVendor advisory
- 2026-07-15 16:55 UTCEPSS rescore
- 2026-07-15 16:49 UTCCISA KEV update
- 2026-07-15 15:04 UTCCISA KEV update
- 2026-07-15 14:51 UTCVendor advisory
- 2026-07-15 10:39 UTCVendor advisory
- 2026-07-15 06:26 UTCVendor advisory
- 2026-07-15 02:16 UTCVendor advisory
- 2026-07-14 22:06 UTCVendor advisory
- 2026-07-14 18:05 UTCCISA KEV update
- 2026-07-14 17:54 UTCVendor advisory
- 2026-07-14 13:41 UTCVendor advisory
- 2026-07-14 09:30 UTCVendor advisory
- 2026-07-14 05:16 UTCVendor advisory
- 2026-07-14 01:06 UTCVendor advisory
- 2026-07-13 20:55 UTCVendor advisory
- 2026-07-13 17:07 UTCCISA KEV update
- 2026-07-13 16:44 UTCVendor advisory
- 2026-07-13 12:33 UTCVendor advisory
- 2026-07-13 08:23 UTCVendor advisory
- 2026-07-13 04:12 UTCVendor advisory
- 2026-07-13 00:01 UTCVendor advisory
- 2026-07-12 19:50 UTCVendor advisory
- 2026-07-12 15:39 UTCVendor advisory
- 2026-07-12 11:28 UTCVendor advisory
- 2026-07-12 07:18 UTCVendor advisory
- 2026-07-12 03:07 UTCVendor advisory
- 2026-07-11 22:55 UTCVendor advisory
- 2026-07-11 18:45 UTCVendor advisory
- 2026-07-11 14:35 UTCVendor advisory
- 2026-07-11 10:25 UTCVendor advisory
- 2026-07-11 06:14 UTCVendor advisory
- 2026-07-11 02:03 UTCVendor advisory
- 2026-07-10 21:52 UTCVendor advisory
- 2026-07-10 17:52 UTCCISA KEV update
- 2026-07-10 17:41 UTCVendor advisory
- 2026-07-10 13:30 UTCVendor advisory
- 2026-07-10 09:17 UTCVendor advisory
- 2026-07-10 05:05 UTCVendor advisory
- 2026-07-10 00:54 UTCVendor advisory
- 2026-07-09 20:44 UTCVendor advisory
- 2026-07-09 16:32 UTCVendor advisory
- 2026-07-09 12:22 UTCVendor advisory
- 2026-07-09 08:12 UTCVendor advisory
- 2026-07-09 04:01 UTCVendor advisory
- 2026-07-08 23:51 UTCVendor advisory
- 2026-07-08 19:41 UTCVendor advisory
- 2026-07-08 15:30 UTCVendor advisory
- 2026-07-08 11:19 UTCVendor advisory
- 2026-07-08 07:09 UTCVendor advisory
- 2026-07-08 02:58 UTCVendor advisory
- 2026-07-07 22:46 UTCVendor advisory
- 2026-07-07 19:01 UTCCISA KEV update
Publicly available exploits
(10 references)Working exploit code is in the public domain (8 GitHub PoCs) (2 Exploit-DB entries). Defenders should treat patch urgency accordingly — public PoCs typically lead to mass-exploitation within 24-72 hours.
- GitHub PoClizhianyuguangming/TomcatScanProFirst seen Aug 29, 2024
tomcat自动化漏洞扫描利用工具,支持批量弱口令检测、后台部署war包getshell、CVE-2017-12615 文件上传、CVE-2020-1938/CNVD-2020-10487 文件包含
Open source ↗ - GitHub PoCtpt11fb/AttackTomcatFirst seen Nov 13, 2022
Tomcat常见漏洞GUI利用工具。CVE-2017-12615 PUT文件上传漏洞、tomcat-pass-getshell 弱认证部署war包、弱口令爆破、CVE-2020-1938 Tomcat AJP文件读取/包含
Open source ↗ - Open source ↗GitHub PoCHancheng-Lei/Hacking-Vulnerability-CVE-2020-1938-GhostcatFirst seen Mar 28, 2021
- Exploit-DBEDB-49039✓ verifiedFirst seen Nov 13, 2020
Apache Tomcat - AJP 'Ghostcat' File Read/Inclusion (Metasploit)
Open source ↗ - GitHub PoC00theway/Ghostcat-CNVD-2020-10487First seen Feb 22, 2020
Ghostcat read file/code execute,CNVD-2020-10487(CVE-2020-1938)
Open source ↗ - GitHub PoCfairyming/CVE-2020-1938First seen Feb 21, 2020
在一定条件下可执行命令
Open source ↗ - GitHub PoCsv3nbeast/CVE-2020-1938-Tomact-file_include-file_readFirst seen Feb 21, 2020
Tomcat的文件包含及文件读取漏洞利用POC
Open source ↗ - GitHub PoClaolisafe/CVE-2020-1938First seen Feb 21, 2020
CVE-2020-1938漏洞复现
Open source ↗ - GitHub PoCwoaiqiukui/CVE-2020-1938TomcatAjpScannerFirst seen Feb 21, 2020
批量扫描TomcatAJP漏洞
Open source ↗ - Exploit-DBEDB-48143First seen Feb 20, 2020
Apache Tomcat - AJP 'Ghostcat File Read/Inclusion
Open source ↗
Frequently asked(6)
What is CVE-2020-1938?
When was CVE-2020-1938 disclosed?
Is CVE-2020-1938 actively exploited?
What is the CVSS score of CVE-2020-1938?
Which products are affected by CVE-2020-1938?
How do I remediate CVE-2020-1938?
Dependency Blast Radius
See which npm, PyPI, Go, and Maven packages are affected by CVE-2020-1938
Is Your Infrastructure Affected by CVE-2020-1938?
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.