RHSA-2024:0474MediumCVSS 6.1

Red Hat Security Advisory: tomcat security update

Published
January 25, 2024
Last Modified
August 4, 2026

🔗 CVE IDs covered (4)

📋 Description

CVE-2023-41080 — tomcat: Open Redirect vulnerability in FORM authentication CVE-2023-42794 — tomcat: FileUpload: DoS due to accumulation of temporary files on Windows CVE-2023-42795 — tomcat: improper cleaning of recycled objects could lead to information leak CVE-2023-45648 — tomcat: incorrectly parsed http trailer headers can cause request smuggling

🎯 Affected products10

  • Red Hat Enterprise Linux AppStream (v. 9)
  • tomcat-1:9.0.62-37.el9_3.1.noarch as a component of Red Hat Enterprise Linux AppStream (v. 9)
  • tomcat-1:9.0.62-37.el9_3.1.src as a component of Red Hat Enterprise Linux AppStream (v. 9)
  • tomcat-admin-webapps-1:9.0.62-37.el9_3.1.noarch as a component of Red Hat Enterprise Linux AppStream (v. 9)
  • tomcat-docs-webapp-1:9.0.62-37.el9_3.1.noarch as a component of Red Hat Enterprise Linux AppStream (v. 9)
  • tomcat-el-3.0-api-1:9.0.62-37.el9_3.1.noarch as a component of Red Hat Enterprise Linux AppStream (v. 9)
  • tomcat-jsp-2.3-api-1:9.0.62-37.el9_3.1.noarch as a component of Red Hat Enterprise Linux AppStream (v. 9)
  • tomcat-lib-1:9.0.62-37.el9_3.1.noarch as a component of Red Hat Enterprise Linux AppStream (v. 9)
  • tomcat-servlet-4.0-api-1:9.0.62-37.el9_3.1.noarch as a component of Red Hat Enterprise Linux AppStream (v. 9)
  • tomcat-webapps-1:9.0.62-37.el9_3.1.noarch as a component of Red Hat Enterprise Linux AppStream (v. 9)

✅ Remediation

For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Workaround: No mitigation is currently available for this flaw.

🔗 References (7)