Red Hat Security Advisory: Red Hat JBoss Web Server 3.1 Service Pack 10 security update
🔗 CVE IDs covered (2)
📋 Description
CVE-2020-1935 — tomcat: Mishandling of Transfer-Encoding header allows for HTTP request smuggling CVE-2020-13935 — tomcat: multiple requests with invalid payload length in a WebSocket frame could lead to DoS
🎯 Affected products54
- Red Hat JBoss Web Server 3.1 for RHEL 6
- Red Hat JBoss Web Server 3.1 for RHEL 7
- tomcat7-0:7.0.70-41.ep7.el6.noarch as a component of Red Hat JBoss Web Server 3.1 for RHEL 6
- tomcat7-0:7.0.70-41.ep7.el6.src as a component of Red Hat JBoss Web Server 3.1 for RHEL 6
- tomcat7-0:7.0.70-41.ep7.el7.noarch as a component of Red Hat JBoss Web Server 3.1 for RHEL 7
- tomcat7-0:7.0.70-41.ep7.el7.src as a component of Red Hat JBoss Web Server 3.1 for RHEL 7
- tomcat7-admin-webapps-0:7.0.70-41.ep7.el6.noarch as a component of Red Hat JBoss Web Server 3.1 for RHEL 6
- tomcat7-admin-webapps-0:7.0.70-41.ep7.el7.noarch as a component of Red Hat JBoss Web Server 3.1 for RHEL 7
- tomcat7-docs-webapp-0:7.0.70-41.ep7.el6.noarch as a component of Red Hat JBoss Web Server 3.1 for RHEL 6
- tomcat7-docs-webapp-0:7.0.70-41.ep7.el7.noarch as a component of Red Hat JBoss Web Server 3.1 for RHEL 7
- tomcat7-el-2.2-api-0:7.0.70-41.ep7.el6.noarch as a component of Red Hat JBoss Web Server 3.1 for RHEL 6
- tomcat7-el-2.2-api-0:7.0.70-41.ep7.el7.noarch as a component of Red Hat JBoss Web Server 3.1 for RHEL 7
- tomcat7-javadoc-0:7.0.70-41.ep7.el6.noarch as a component of Red Hat JBoss Web Server 3.1 for RHEL 6
- tomcat7-javadoc-0:7.0.70-41.ep7.el7.noarch as a component of Red Hat JBoss Web Server 3.1 for RHEL 7
- tomcat7-jsp-2.2-api-0:7.0.70-41.ep7.el6.noarch as a component of Red Hat JBoss Web Server 3.1 for RHEL 6
- tomcat7-jsp-2.2-api-0:7.0.70-41.ep7.el7.noarch as a component of Red Hat JBoss Web Server 3.1 for RHEL 7
- tomcat7-jsvc-0:7.0.70-41.ep7.el6.noarch as a component of Red Hat JBoss Web Server 3.1 for RHEL 6
- tomcat7-jsvc-0:7.0.70-41.ep7.el7.noarch as a component of Red Hat JBoss Web Server 3.1 for RHEL 7
- tomcat7-lib-0:7.0.70-41.ep7.el6.noarch as a component of Red Hat JBoss Web Server 3.1 for RHEL 6
- tomcat7-lib-0:7.0.70-41.ep7.el7.noarch as a component of Red Hat JBoss Web Server 3.1 for RHEL 7
- tomcat7-log4j-0:7.0.70-41.ep7.el6.noarch as a component of Red Hat JBoss Web Server 3.1 for RHEL 6
- tomcat7-log4j-0:7.0.70-41.ep7.el7.noarch as a component of Red Hat JBoss Web Server 3.1 for RHEL 7
- tomcat7-selinux-0:7.0.70-41.ep7.el6.noarch as a component of Red Hat JBoss Web Server 3.1 for RHEL 6
- tomcat7-selinux-0:7.0.70-41.ep7.el7.noarch as a component of Red Hat JBoss Web Server 3.1 for RHEL 7
- tomcat7-servlet-3.0-api-0:7.0.70-41.ep7.el6.noarch as a component of Red Hat JBoss Web Server 3.1 for RHEL 6
- tomcat7-servlet-3.0-api-0:7.0.70-41.ep7.el7.noarch as a component of Red Hat JBoss Web Server 3.1 for RHEL 7
- tomcat7-webapps-0:7.0.70-41.ep7.el6.noarch as a component of Red Hat JBoss Web Server 3.1 for RHEL 6
- tomcat7-webapps-0:7.0.70-41.ep7.el7.noarch as a component of Red Hat JBoss Web Server 3.1 for RHEL 7
- tomcat8-0:8.0.36-45.ep7.el6.noarch as a component of Red Hat JBoss Web Server 3.1 for RHEL 6
- tomcat8-0:8.0.36-45.ep7.el6.src as a component of Red Hat JBoss Web Server 3.1 for RHEL 6
- +24 more not shown
✅ Remediation
Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: Workaround for Red Hat Satellite 6 is to add iptables rule to deny TCP requests of Tomcat that are not originating from the Satellite. For other Red Hat products, either mitigation isn't available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update as soon as possible.
🔗 References (5)
- selfhttps://access.redhat.com/errata/RHSA-2020:3303
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1806835
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1857024
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2020/rhsa-2020_3303.json