RHSA-2020:4004HighCVSS 7.5
Red Hat Security Advisory: tomcat security and bug fix update
🔗 CVE IDs covered (2)
📋 Description
CVE-2019-17563 — tomcat: Session fixation when using FORM authentication CVE-2020-13935 — tomcat: multiple requests with invalid payload length in a WebSocket frame could lead to DoS
🎯 Affected products58
- Red Hat Enterprise Linux Client (v. 7)
- Red Hat Enterprise Linux Client Optional (v. 7)
- Red Hat Enterprise Linux ComputeNode (v. 7)
- Red Hat Enterprise Linux ComputeNode Optional (v. 7)
- Red Hat Enterprise Linux Server (v. 7)
- Red Hat Enterprise Linux Server Optional (v. 7)
- Red Hat Enterprise Linux Workstation (v. 7)
- Red Hat Enterprise Linux Workstation Optional (v. 7)
- tomcat-0:7.0.76-15.el7.noarch as a component of Red Hat Enterprise Linux Client Optional (v. 7)
- tomcat-0:7.0.76-15.el7.noarch as a component of Red Hat Enterprise Linux ComputeNode Optional (v. 7)
- tomcat-0:7.0.76-15.el7.noarch as a component of Red Hat Enterprise Linux Server (v. 7)
- tomcat-0:7.0.76-15.el7.noarch as a component of Red Hat Enterprise Linux Server Optional (v. 7)
- tomcat-0:7.0.76-15.el7.noarch as a component of Red Hat Enterprise Linux Workstation (v. 7)
- tomcat-0:7.0.76-15.el7.src as a component of Red Hat Enterprise Linux Client (v. 7)
- tomcat-0:7.0.76-15.el7.src as a component of Red Hat Enterprise Linux ComputeNode (v. 7)
- tomcat-0:7.0.76-15.el7.src as a component of Red Hat Enterprise Linux Server (v. 7)
- tomcat-0:7.0.76-15.el7.src as a component of Red Hat Enterprise Linux Workstation (v. 7)
- tomcat-admin-webapps-0:7.0.76-15.el7.noarch as a component of Red Hat Enterprise Linux Client Optional (v. 7)
- tomcat-admin-webapps-0:7.0.76-15.el7.noarch as a component of Red Hat Enterprise Linux ComputeNode Optional (v. 7)
- tomcat-admin-webapps-0:7.0.76-15.el7.noarch as a component of Red Hat Enterprise Linux Server (v. 7)
- tomcat-admin-webapps-0:7.0.76-15.el7.noarch as a component of Red Hat Enterprise Linux Server Optional (v. 7)
- tomcat-admin-webapps-0:7.0.76-15.el7.noarch as a component of Red Hat Enterprise Linux Workstation (v. 7)
- tomcat-docs-webapp-0:7.0.76-15.el7.noarch as a component of Red Hat Enterprise Linux Client Optional (v. 7)
- tomcat-docs-webapp-0:7.0.76-15.el7.noarch as a component of Red Hat Enterprise Linux ComputeNode Optional (v. 7)
- tomcat-docs-webapp-0:7.0.76-15.el7.noarch as a component of Red Hat Enterprise Linux Server Optional (v. 7)
- tomcat-docs-webapp-0:7.0.76-15.el7.noarch as a component of Red Hat Enterprise Linux Workstation Optional (v. 7)
- tomcat-el-2.2-api-0:7.0.76-15.el7.noarch as a component of Red Hat Enterprise Linux Client Optional (v. 7)
- tomcat-el-2.2-api-0:7.0.76-15.el7.noarch as a component of Red Hat Enterprise Linux ComputeNode Optional (v. 7)
- tomcat-el-2.2-api-0:7.0.76-15.el7.noarch as a component of Red Hat Enterprise Linux Server (v. 7)
- tomcat-el-2.2-api-0:7.0.76-15.el7.noarch as a component of Red Hat Enterprise Linux Server Optional (v. 7)
- +28 more not shown
✅ Remediation
For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Workaround: Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update as soon as possible.
🔗 References (11)
- selfhttps://access.redhat.com/errata/RHSA-2020:4004
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/7/html/7.9_release_notes/index
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1523112
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1629162
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1785711
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1795645
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1822453
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1831127
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1857024
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2020/rhsa-2020_4004.json