Red Hat Security Advisory: Red Hat JBoss Web Server 6.2.3 release and security update
🔗 CVE IDs covered (7)
📋 Description
CVE-2026-24880 — Apache Tomcat: Apache Tomcat: HTTP Request/Response Smuggling via invalid chunk extension CVE-2026-25854 — Apache Tomcat: Apache Tomcat: Open Redirect vulnerability via LoadBalancerDrainingValve CVE-2026-29145 — Apache Tomcat: Apache Tomcat: Authentication bypass due to CLIENT_CERT soft fail misconfiguration CVE-2026-29146 — Apache Tomcat: Apache Tomcat: Information disclosure via Padding Oracle vulnerability in EncryptInterceptor CVE-2026-34483 — Apache Tomcat: Apache Tomcat: Information disclosure due to improper encoding in JsonAccessLogValve CVE-2026-34487 — Apache Tomcat: Apache Tomcat: Information disclosure via sensitive data in log files CVE-2026-34500 — Apache Tomcat: Apache Tomcat: Authentication bypass via client certificate misconfiguration
🔗 References (11)
- selfhttps://access.redhat.com/errata/RHSA-2026:20405
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://docs.redhat.com/en/documentation/red_hat_jboss_web_server/6.2/html/red_hat_jboss_web_server_6.2_service_pack_3_release_notes/index
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2457020
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2457037
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2457038
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2457039
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2457040
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2457043
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2457044
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_20405.json