[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248268

 
 

909

 
 

195051

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

CESA-2019:2205 -- centos 7 tomcat

ID: oval:org.secpod.oval:def:205275Date: (C)2019-09-17   (M)2023-12-20
Class: PATCHFamily: unix




Apache Tomcat is a servlet container for the Java Servlet and JavaServer Pages technologies. Security Fix: * tomcat: Incorrect handling of empty string URL in security constraints can lead to unintended exposure of resources * tomcat: Late application of security constraints can lead to resource exposure for unauthorised users * tomcat: Insecure defaults in CORS filter enable "supportsCredentials" for all origins * tomcat: Host name verification missing in WebSocket client For more details about the security issue, including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page listed in the References section. Additional Changes: For detailed information on changes in this release, see the Red Hat Enterprise Linux 7.7 Release Notes linked from the References section.

Platform:
CentOS 7
Product:
tomcat
Reference:
CESA-2019:2205
CVE-2018-1304
CVE-2018-1305
CVE-2018-8014
CVE-2018-8034
CVE    4
CVE-2018-1305
CVE-2018-1304
CVE-2018-8034
CVE-2018-8014
...
CPE    182
cpe:/o:centos:centos:7
cpe:/a:apache:tomcat:8.5.7
cpe:/a:apache:tomcat:8.5.8
cpe:/a:apache:tomcat:8.5.9
...

© SecPod Technologies