RHSA-2023:6207MediumCVSS 5.3

Red Hat Security Advisory: Red Hat JBoss Web Server 5.7.6 release and security update

Published
October 31, 2023
Last Modified
August 4, 2026

🔗 CVE IDs covered (2)

📋 Description

CVE-2023-42795 — tomcat: improper cleaning of recycled objects could lead to information leak CVE-2023-45648 — tomcat: incorrectly parsed http trailer headers can cause request smuggling

🎯 Affected products1

  • Red Hat JBoss Web Server 5

✅ Remediation

Before applying the update, back up your existing Red Hat JBoss Web Server installation, including all applications and configuration files. The References section of this erratum contains a download link for the update. You must be logged in to download the update. Workaround: No mitigation is currently available for this flaw.

🔗 References (5)