RHSA-2020:5020LowCVSS 4.3

Red Hat Security Advisory: tomcat security update

Published
November 10, 2020
Last Modified
August 4, 2026

🔗 CVE IDs covered (1)

📋 Description

CVE-2020-1935 — tomcat: Mishandling of Transfer-Encoding header allows for HTTP request smuggling

🎯 Affected products55

  • Red Hat Enterprise Linux Client (v. 7)
  • Red Hat Enterprise Linux Client Optional (v. 7)
  • Red Hat Enterprise Linux ComputeNode Optional (v. 7)
  • Red Hat Enterprise Linux Server (v. 7)
  • Red Hat Enterprise Linux Server Optional (v. 7)
  • Red Hat Enterprise Linux Workstation (v. 7)
  • Red Hat Enterprise Linux Workstation Optional (v. 7)
  • tomcat-0:7.0.76-16.el7_9.noarch as a component of Red Hat Enterprise Linux Client Optional (v. 7)
  • tomcat-0:7.0.76-16.el7_9.noarch as a component of Red Hat Enterprise Linux ComputeNode Optional (v. 7)
  • tomcat-0:7.0.76-16.el7_9.noarch as a component of Red Hat Enterprise Linux Server (v. 7)
  • tomcat-0:7.0.76-16.el7_9.noarch as a component of Red Hat Enterprise Linux Server Optional (v. 7)
  • tomcat-0:7.0.76-16.el7_9.noarch as a component of Red Hat Enterprise Linux Workstation (v. 7)
  • tomcat-0:7.0.76-16.el7_9.src as a component of Red Hat Enterprise Linux Client (v. 7)
  • tomcat-0:7.0.76-16.el7_9.src as a component of Red Hat Enterprise Linux Server (v. 7)
  • tomcat-0:7.0.76-16.el7_9.src as a component of Red Hat Enterprise Linux Workstation (v. 7)
  • tomcat-admin-webapps-0:7.0.76-16.el7_9.noarch as a component of Red Hat Enterprise Linux Client Optional (v. 7)
  • tomcat-admin-webapps-0:7.0.76-16.el7_9.noarch as a component of Red Hat Enterprise Linux ComputeNode Optional (v. 7)
  • tomcat-admin-webapps-0:7.0.76-16.el7_9.noarch as a component of Red Hat Enterprise Linux Server (v. 7)
  • tomcat-admin-webapps-0:7.0.76-16.el7_9.noarch as a component of Red Hat Enterprise Linux Server Optional (v. 7)
  • tomcat-admin-webapps-0:7.0.76-16.el7_9.noarch as a component of Red Hat Enterprise Linux Workstation (v. 7)
  • tomcat-docs-webapp-0:7.0.76-16.el7_9.noarch as a component of Red Hat Enterprise Linux Client Optional (v. 7)
  • tomcat-docs-webapp-0:7.0.76-16.el7_9.noarch as a component of Red Hat Enterprise Linux ComputeNode Optional (v. 7)
  • tomcat-docs-webapp-0:7.0.76-16.el7_9.noarch as a component of Red Hat Enterprise Linux Server Optional (v. 7)
  • tomcat-docs-webapp-0:7.0.76-16.el7_9.noarch as a component of Red Hat Enterprise Linux Workstation Optional (v. 7)
  • tomcat-el-2.2-api-0:7.0.76-16.el7_9.noarch as a component of Red Hat Enterprise Linux Client Optional (v. 7)
  • tomcat-el-2.2-api-0:7.0.76-16.el7_9.noarch as a component of Red Hat Enterprise Linux ComputeNode Optional (v. 7)
  • tomcat-el-2.2-api-0:7.0.76-16.el7_9.noarch as a component of Red Hat Enterprise Linux Server (v. 7)
  • tomcat-el-2.2-api-0:7.0.76-16.el7_9.noarch as a component of Red Hat Enterprise Linux Server Optional (v. 7)
  • tomcat-el-2.2-api-0:7.0.76-16.el7_9.noarch as a component of Red Hat Enterprise Linux Workstation (v. 7)
  • tomcat-javadoc-0:7.0.76-16.el7_9.noarch as a component of Red Hat Enterprise Linux Client Optional (v. 7)
  • +25 more not shown

✅ Remediation

For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Workaround: Workaround for Red Hat Satellite 6 is to add iptables rule to deny TCP requests of Tomcat that are not originating from the Satellite. For other Red Hat products, either mitigation isn't available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

🔗 References (4)