RHSA-2021:1030LowCVSS 7.5
Red Hat Security Advisory: tomcat security update
🔗 CVE IDs covered (2)
📋 Description
CVE-2019-17563 — tomcat: Session fixation when using FORM authentication CVE-2020-1935 — tomcat: Mishandling of Transfer-Encoding header allows for HTTP request smuggling
🎯 Affected products32
- Red Hat Enterprise Linux ComputeNode EUS (v. 7.7)
- Red Hat Enterprise Linux ComputeNode Optional EUS (v. 7.7)
- Red Hat Enterprise Linux Server EUS (v. 7.7)
- Red Hat Enterprise Linux Server Optional EUS (v. 7.7)
- tomcat-0:7.0.76-12.el7_7.noarch as a component of Red Hat Enterprise Linux ComputeNode Optional EUS (v. 7.7)
- tomcat-0:7.0.76-12.el7_7.noarch as a component of Red Hat Enterprise Linux Server EUS (v. 7.7)
- tomcat-0:7.0.76-12.el7_7.noarch as a component of Red Hat Enterprise Linux Server Optional EUS (v. 7.7)
- tomcat-0:7.0.76-12.el7_7.src as a component of Red Hat Enterprise Linux ComputeNode EUS (v. 7.7)
- tomcat-0:7.0.76-12.el7_7.src as a component of Red Hat Enterprise Linux Server EUS (v. 7.7)
- tomcat-admin-webapps-0:7.0.76-12.el7_7.noarch as a component of Red Hat Enterprise Linux ComputeNode Optional EUS (v. 7.7)
- tomcat-admin-webapps-0:7.0.76-12.el7_7.noarch as a component of Red Hat Enterprise Linux Server EUS (v. 7.7)
- tomcat-admin-webapps-0:7.0.76-12.el7_7.noarch as a component of Red Hat Enterprise Linux Server Optional EUS (v. 7.7)
- tomcat-docs-webapp-0:7.0.76-12.el7_7.noarch as a component of Red Hat Enterprise Linux ComputeNode Optional EUS (v. 7.7)
- tomcat-docs-webapp-0:7.0.76-12.el7_7.noarch as a component of Red Hat Enterprise Linux Server Optional EUS (v. 7.7)
- tomcat-el-2.2-api-0:7.0.76-12.el7_7.noarch as a component of Red Hat Enterprise Linux ComputeNode Optional EUS (v. 7.7)
- tomcat-el-2.2-api-0:7.0.76-12.el7_7.noarch as a component of Red Hat Enterprise Linux Server EUS (v. 7.7)
- tomcat-el-2.2-api-0:7.0.76-12.el7_7.noarch as a component of Red Hat Enterprise Linux Server Optional EUS (v. 7.7)
- tomcat-javadoc-0:7.0.76-12.el7_7.noarch as a component of Red Hat Enterprise Linux ComputeNode Optional EUS (v. 7.7)
- tomcat-javadoc-0:7.0.76-12.el7_7.noarch as a component of Red Hat Enterprise Linux Server Optional EUS (v. 7.7)
- tomcat-jsp-2.2-api-0:7.0.76-12.el7_7.noarch as a component of Red Hat Enterprise Linux ComputeNode Optional EUS (v. 7.7)
- tomcat-jsp-2.2-api-0:7.0.76-12.el7_7.noarch as a component of Red Hat Enterprise Linux Server EUS (v. 7.7)
- tomcat-jsp-2.2-api-0:7.0.76-12.el7_7.noarch as a component of Red Hat Enterprise Linux Server Optional EUS (v. 7.7)
- tomcat-jsvc-0:7.0.76-12.el7_7.noarch as a component of Red Hat Enterprise Linux ComputeNode Optional EUS (v. 7.7)
- tomcat-jsvc-0:7.0.76-12.el7_7.noarch as a component of Red Hat Enterprise Linux Server Optional EUS (v. 7.7)
- tomcat-lib-0:7.0.76-12.el7_7.noarch as a component of Red Hat Enterprise Linux ComputeNode Optional EUS (v. 7.7)
- tomcat-lib-0:7.0.76-12.el7_7.noarch as a component of Red Hat Enterprise Linux Server EUS (v. 7.7)
- tomcat-lib-0:7.0.76-12.el7_7.noarch as a component of Red Hat Enterprise Linux Server Optional EUS (v. 7.7)
- tomcat-servlet-3.0-api-0:7.0.76-12.el7_7.noarch as a component of Red Hat Enterprise Linux ComputeNode EUS (v. 7.7)
- tomcat-servlet-3.0-api-0:7.0.76-12.el7_7.noarch as a component of Red Hat Enterprise Linux Server EUS (v. 7.7)
- tomcat-webapps-0:7.0.76-12.el7_7.noarch as a component of Red Hat Enterprise Linux ComputeNode Optional EUS (v. 7.7)
- +2 more not shown
✅ Remediation
For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Workaround: Workaround for Red Hat Satellite 6 is to add iptables rule to deny TCP requests of Tomcat that are not originating from the Satellite. For other Red Hat products, either mitigation isn't available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
🔗 References (5)
- selfhttps://access.redhat.com/errata/RHSA-2021:1030
- externalhttps://access.redhat.com/security/updates/classification/#low
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1785711
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1806835
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2021/rhsa-2021_1030.json