RHSA-2023:7065MediumCVSS 7.5

Red Hat Security Advisory: tomcat security and bug fix update

Published
November 14, 2023
Last Modified
August 4, 2026

🔗 CVE IDs covered (3)

📋 Description

CVE-2023-24998 — FileUpload: FileUpload DoS with excessive parts CVE-2023-28708 — tomcat: not including the secure attribute causes information disclosure CVE-2023-28709 — tomcat: Fix for CVE-2023-24998 was incomplete

🎯 Affected products10

  • Red Hat Enterprise Linux AppStream (v. 8)
  • tomcat-1:9.0.62-27.el8_9.noarch as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • tomcat-1:9.0.62-27.el8_9.src as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • tomcat-admin-webapps-1:9.0.62-27.el8_9.noarch as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • tomcat-docs-webapp-1:9.0.62-27.el8_9.noarch as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • tomcat-el-3.0-api-1:9.0.62-27.el8_9.noarch as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • tomcat-jsp-2.3-api-1:9.0.62-27.el8_9.noarch as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • tomcat-lib-1:9.0.62-27.el8_9.noarch as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • tomcat-servlet-4.0-api-1:9.0.62-27.el8_9.noarch as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • tomcat-webapps-1:9.0.62-27.el8_9.noarch as a component of Red Hat Enterprise Linux AppStream (v. 8)

✅ Remediation

For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Workaround: For possible impact and workaround, please refer to: https://access.redhat.com/solutions/7004796 Workaround: No mitigation is currently available that meets Red Hat Product Security's standards for usability, deployment, applicability, or stability.

🔗 References (9)