Red Hat Security Advisory: Red Hat JBoss Web Server 3.1 Service Pack 10 security update
🔗 CVE IDs covered (2)
📋 Description
CVE-2020-1935 — tomcat: Mishandling of Transfer-Encoding header allows for HTTP request smuggling CVE-2020-13935 — tomcat: multiple requests with invalid payload length in a WebSocket frame could lead to DoS
🎯 Affected products1
- Red Hat JBoss Web Server 3.1
✅ Remediation
Before applying the update, back up your existing installation, including all applications, configuration files, databases and database settings, and so on. The References section of this erratum contains a download link for the update. You must be logged in to download the update. Workaround: Workaround for Red Hat Satellite 6 is to add iptables rule to deny TCP requests of Tomcat that are not originating from the Satellite. For other Red Hat products, either mitigation isn't available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update as soon as possible.
🔗 References (7)
- selfhttps://access.redhat.com/errata/RHSA-2020:3305
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://access.redhat.com/jbossnetwork/restricted/listSoftware.html?product=webserver&downloadType=securityPatches&version=3.1
- externalhttps://access.redhat.com/documentation/en-us/red_hat_jboss_web_server/3.1/
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1806835
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1857024
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2020/rhsa-2020_3305.json