[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248364

 
 

909

 
 

195388

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

RHSA-2019:2205-01 -- Redhat tomcat, tomcat-servlet-3.0-api

ID: oval:org.secpod.oval:def:503302Date: (C)2019-10-04   (M)2023-12-20
Class: PATCHFamily: unix




Apache Tomcat is a servlet container for the Java Servlet and JavaServer Pages technologies. Security Fix: * tomcat: Incorrect handling of empty string URL in security constraints can lead to unintended exposure of resources * tomcat: Late application of security constraints can lead to resource exposure for unauthorised users * tomcat: Insecure defaults in CORS filter enable "supportsCredentials" for all origins * tomcat: Host name verification missing in WebSocket client For more details about the security issue, including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page listed in the References section. Additional Changes: For detailed information on changes in this release, see the Red Hat Enterprise Linux 7.7 Release Notes linked from the References section.

Platform:
Red Hat Enterprise Linux 7
Product:
tomcat
tomcat-servlet
Reference:
RHSA-2019:2205-01
CVE-2018-1304
CVE-2018-1305
CVE-2018-8014
CVE-2018-8034
CVE    4
CVE-2018-1305
CVE-2018-1304
CVE-2018-8034
CVE-2018-8014
...
CPE    183
cpe:/a:apache:tomcat:8.5.7
cpe:/a:apache:tomcat:8.5.8
cpe:/a:apache:tomcat:8.5.9
cpe:/a:apache:tomcat:8.0.0:rc1
...

© SecPod Technologies