RHSA-2023:6206MediumCVSS 5.3

Red Hat Security Advisory: Red Hat JBoss Web Server 5.7.6 release and security update

Published
October 31, 2023
Last Modified
August 4, 2026

🔗 CVE IDs covered (2)

📋 Description

CVE-2023-42795 — tomcat: improper cleaning of recycled objects could lead to information leak CVE-2023-45648 — tomcat: incorrectly parsed http trailer headers can cause request smuggling

🎯 Affected products38

  • Red Hat JBoss Web Server 5.7 for RHEL 7 Server
  • Red Hat JBoss Web Server 5.7 for RHEL 8
  • Red Hat JBoss Web Server 5.7 for RHEL 9
  • jws5-tomcat-0:9.0.62-18.redhat_00016.1.el7jws.noarch as a component of Red Hat JBoss Web Server 5.7 for RHEL 7 Server
  • jws5-tomcat-0:9.0.62-18.redhat_00016.1.el7jws.src as a component of Red Hat JBoss Web Server 5.7 for RHEL 7 Server
  • jws5-tomcat-0:9.0.62-18.redhat_00016.1.el8jws.noarch as a component of Red Hat JBoss Web Server 5.7 for RHEL 8
  • jws5-tomcat-0:9.0.62-18.redhat_00016.1.el8jws.src as a component of Red Hat JBoss Web Server 5.7 for RHEL 8
  • jws5-tomcat-0:9.0.62-18.redhat_00016.1.el9jws.noarch as a component of Red Hat JBoss Web Server 5.7 for RHEL 9
  • jws5-tomcat-0:9.0.62-18.redhat_00016.1.el9jws.src as a component of Red Hat JBoss Web Server 5.7 for RHEL 9
  • jws5-tomcat-admin-webapps-0:9.0.62-18.redhat_00016.1.el7jws.noarch as a component of Red Hat JBoss Web Server 5.7 for RHEL 7 Server
  • jws5-tomcat-admin-webapps-0:9.0.62-18.redhat_00016.1.el8jws.noarch as a component of Red Hat JBoss Web Server 5.7 for RHEL 8
  • jws5-tomcat-admin-webapps-0:9.0.62-18.redhat_00016.1.el9jws.noarch as a component of Red Hat JBoss Web Server 5.7 for RHEL 9
  • jws5-tomcat-docs-webapp-0:9.0.62-18.redhat_00016.1.el7jws.noarch as a component of Red Hat JBoss Web Server 5.7 for RHEL 7 Server
  • jws5-tomcat-docs-webapp-0:9.0.62-18.redhat_00016.1.el8jws.noarch as a component of Red Hat JBoss Web Server 5.7 for RHEL 8
  • jws5-tomcat-docs-webapp-0:9.0.62-18.redhat_00016.1.el9jws.noarch as a component of Red Hat JBoss Web Server 5.7 for RHEL 9
  • jws5-tomcat-el-3.0-api-0:9.0.62-18.redhat_00016.1.el7jws.noarch as a component of Red Hat JBoss Web Server 5.7 for RHEL 7 Server
  • jws5-tomcat-el-3.0-api-0:9.0.62-18.redhat_00016.1.el8jws.noarch as a component of Red Hat JBoss Web Server 5.7 for RHEL 8
  • jws5-tomcat-el-3.0-api-0:9.0.62-18.redhat_00016.1.el9jws.noarch as a component of Red Hat JBoss Web Server 5.7 for RHEL 9
  • jws5-tomcat-java-jdk11-0:9.0.62-18.redhat_00016.1.el7jws.noarch as a component of Red Hat JBoss Web Server 5.7 for RHEL 7 Server
  • jws5-tomcat-java-jdk8-0:9.0.62-18.redhat_00016.1.el7jws.noarch as a component of Red Hat JBoss Web Server 5.7 for RHEL 7 Server
  • jws5-tomcat-javadoc-0:9.0.62-18.redhat_00016.1.el7jws.noarch as a component of Red Hat JBoss Web Server 5.7 for RHEL 7 Server
  • jws5-tomcat-javadoc-0:9.0.62-18.redhat_00016.1.el8jws.noarch as a component of Red Hat JBoss Web Server 5.7 for RHEL 8
  • jws5-tomcat-javadoc-0:9.0.62-18.redhat_00016.1.el9jws.noarch as a component of Red Hat JBoss Web Server 5.7 for RHEL 9
  • jws5-tomcat-jsp-2.3-api-0:9.0.62-18.redhat_00016.1.el7jws.noarch as a component of Red Hat JBoss Web Server 5.7 for RHEL 7 Server
  • jws5-tomcat-jsp-2.3-api-0:9.0.62-18.redhat_00016.1.el8jws.noarch as a component of Red Hat JBoss Web Server 5.7 for RHEL 8
  • jws5-tomcat-jsp-2.3-api-0:9.0.62-18.redhat_00016.1.el9jws.noarch as a component of Red Hat JBoss Web Server 5.7 for RHEL 9
  • jws5-tomcat-lib-0:9.0.62-18.redhat_00016.1.el7jws.noarch as a component of Red Hat JBoss Web Server 5.7 for RHEL 7 Server
  • jws5-tomcat-lib-0:9.0.62-18.redhat_00016.1.el8jws.noarch as a component of Red Hat JBoss Web Server 5.7 for RHEL 8
  • jws5-tomcat-lib-0:9.0.62-18.redhat_00016.1.el9jws.noarch as a component of Red Hat JBoss Web Server 5.7 for RHEL 9
  • jws5-tomcat-selinux-0:9.0.62-18.redhat_00016.1.el7jws.noarch as a component of Red Hat JBoss Web Server 5.7 for RHEL 7 Server
  • +8 more not shown

✅ Remediation

Before applying the update, back up your existing Red Hat JBoss Web Server installation, including all applications and configuration files. For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Workaround: No mitigation is currently available for this flaw.

🔗 References (5)