RHSA-2023:6206MediumCVSS 5.3
Red Hat Security Advisory: Red Hat JBoss Web Server 5.7.6 release and security update
🔗 CVE IDs covered (2)
📋 Description
CVE-2023-42795 — tomcat: improper cleaning of recycled objects could lead to information leak CVE-2023-45648 — tomcat: incorrectly parsed http trailer headers can cause request smuggling
🎯 Affected products38
- Red Hat JBoss Web Server 5.7 for RHEL 7 Server
- Red Hat JBoss Web Server 5.7 for RHEL 8
- Red Hat JBoss Web Server 5.7 for RHEL 9
- jws5-tomcat-0:9.0.62-18.redhat_00016.1.el7jws.noarch as a component of Red Hat JBoss Web Server 5.7 for RHEL 7 Server
- jws5-tomcat-0:9.0.62-18.redhat_00016.1.el7jws.src as a component of Red Hat JBoss Web Server 5.7 for RHEL 7 Server
- jws5-tomcat-0:9.0.62-18.redhat_00016.1.el8jws.noarch as a component of Red Hat JBoss Web Server 5.7 for RHEL 8
- jws5-tomcat-0:9.0.62-18.redhat_00016.1.el8jws.src as a component of Red Hat JBoss Web Server 5.7 for RHEL 8
- jws5-tomcat-0:9.0.62-18.redhat_00016.1.el9jws.noarch as a component of Red Hat JBoss Web Server 5.7 for RHEL 9
- jws5-tomcat-0:9.0.62-18.redhat_00016.1.el9jws.src as a component of Red Hat JBoss Web Server 5.7 for RHEL 9
- jws5-tomcat-admin-webapps-0:9.0.62-18.redhat_00016.1.el7jws.noarch as a component of Red Hat JBoss Web Server 5.7 for RHEL 7 Server
- jws5-tomcat-admin-webapps-0:9.0.62-18.redhat_00016.1.el8jws.noarch as a component of Red Hat JBoss Web Server 5.7 for RHEL 8
- jws5-tomcat-admin-webapps-0:9.0.62-18.redhat_00016.1.el9jws.noarch as a component of Red Hat JBoss Web Server 5.7 for RHEL 9
- jws5-tomcat-docs-webapp-0:9.0.62-18.redhat_00016.1.el7jws.noarch as a component of Red Hat JBoss Web Server 5.7 for RHEL 7 Server
- jws5-tomcat-docs-webapp-0:9.0.62-18.redhat_00016.1.el8jws.noarch as a component of Red Hat JBoss Web Server 5.7 for RHEL 8
- jws5-tomcat-docs-webapp-0:9.0.62-18.redhat_00016.1.el9jws.noarch as a component of Red Hat JBoss Web Server 5.7 for RHEL 9
- jws5-tomcat-el-3.0-api-0:9.0.62-18.redhat_00016.1.el7jws.noarch as a component of Red Hat JBoss Web Server 5.7 for RHEL 7 Server
- jws5-tomcat-el-3.0-api-0:9.0.62-18.redhat_00016.1.el8jws.noarch as a component of Red Hat JBoss Web Server 5.7 for RHEL 8
- jws5-tomcat-el-3.0-api-0:9.0.62-18.redhat_00016.1.el9jws.noarch as a component of Red Hat JBoss Web Server 5.7 for RHEL 9
- jws5-tomcat-java-jdk11-0:9.0.62-18.redhat_00016.1.el7jws.noarch as a component of Red Hat JBoss Web Server 5.7 for RHEL 7 Server
- jws5-tomcat-java-jdk8-0:9.0.62-18.redhat_00016.1.el7jws.noarch as a component of Red Hat JBoss Web Server 5.7 for RHEL 7 Server
- jws5-tomcat-javadoc-0:9.0.62-18.redhat_00016.1.el7jws.noarch as a component of Red Hat JBoss Web Server 5.7 for RHEL 7 Server
- jws5-tomcat-javadoc-0:9.0.62-18.redhat_00016.1.el8jws.noarch as a component of Red Hat JBoss Web Server 5.7 for RHEL 8
- jws5-tomcat-javadoc-0:9.0.62-18.redhat_00016.1.el9jws.noarch as a component of Red Hat JBoss Web Server 5.7 for RHEL 9
- jws5-tomcat-jsp-2.3-api-0:9.0.62-18.redhat_00016.1.el7jws.noarch as a component of Red Hat JBoss Web Server 5.7 for RHEL 7 Server
- jws5-tomcat-jsp-2.3-api-0:9.0.62-18.redhat_00016.1.el8jws.noarch as a component of Red Hat JBoss Web Server 5.7 for RHEL 8
- jws5-tomcat-jsp-2.3-api-0:9.0.62-18.redhat_00016.1.el9jws.noarch as a component of Red Hat JBoss Web Server 5.7 for RHEL 9
- jws5-tomcat-lib-0:9.0.62-18.redhat_00016.1.el7jws.noarch as a component of Red Hat JBoss Web Server 5.7 for RHEL 7 Server
- jws5-tomcat-lib-0:9.0.62-18.redhat_00016.1.el8jws.noarch as a component of Red Hat JBoss Web Server 5.7 for RHEL 8
- jws5-tomcat-lib-0:9.0.62-18.redhat_00016.1.el9jws.noarch as a component of Red Hat JBoss Web Server 5.7 for RHEL 9
- jws5-tomcat-selinux-0:9.0.62-18.redhat_00016.1.el7jws.noarch as a component of Red Hat JBoss Web Server 5.7 for RHEL 7 Server
- +8 more not shown
✅ Remediation
Before applying the update, back up your existing Red Hat JBoss Web Server installation, including all applications and configuration files. For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Workaround: No mitigation is currently available for this flaw.
🔗 References (5)
- selfhttps://access.redhat.com/errata/RHSA-2023:6206
- externalhttps://access.redhat.com/security/updates/classification/#moderate
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2243749
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2243752
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2023/rhsa-2023_6206.json