drucken bookmarks versenden konfigurieren admin pdf Sicherheit: Zwei Probleme in tomcat
Name: |
Zwei Probleme in tomcat |
|
ID: |
RHSA-2019:0130-01 |
|
Distribution: |
Red Hat |
|
Plattformen: |
Red Hat JBoss Web Server |
|
Datum: |
Di, 22. Januar 2019, 16:39 |
|
Referenzen: |
https://access.redhat.com/security/cve/CVE-2018-8034
https://access.redhat.com/security/cve/CVE-2018-11784 |
|
Applikationen: |
Apache Tomcat |
|
Originalnachricht |
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256
===================================================================== Red Hat Security Advisory
Synopsis: Moderate: Red Hat JBoss Web Server 3.1 Service Pack 6 security and bug fix update Advisory ID: RHSA-2019:0130-01 Product: Red Hat JBoss Web Server Advisory URL: https://access.redhat.com/errata/RHSA-2019:0130 Issue date: 2019-01-22 CVE Names: CVE-2018-8034 CVE-2018-11784 =====================================================================
1. Summary:
An update is now available for Red Hat JBoss Web Server 3.1.
Red Hat Product Security has rated this release as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.
2. Description:
Red Hat JBoss Web Server is a fully integrated and certified set of components for hosting Java web applications. It is comprised of the Apache HTTP Server, the Apache Tomcat Servlet container, Apache Tomcat Connector (mod_jk), JBoss HTTP Connector (mod_cluster), Hibernate, and the Tomcat Native library.
This release of Red Hat JBoss Web Server 3.1 Service Pack 6 serves as a replacement for Red Hat JBoss Web Server 3.1, and includes bug fixes, which are documented in the Release Notes document linked to in the References.
Security Fix(es):
* tomcat: host name verification missing in WebSocket client (CVE-2018-8034) * tomcat: Open redirect in default servlet (CVE-2018-11784)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
3. Solution:
Before applying the update, back up your existing Red Hat JBoss Web Server installation (including all applications and configuration files).
For details on how to apply this update, refer to:
https://access.redhat.com/articles/11258
4. Bugs fixed (https://bugzilla.redhat.com/):
1607580 - CVE-2018-8034 tomcat: host name verification missing in WebSocket client 1636512 - CVE-2018-11784 tomcat: Open redirect in default servlet
5. JIRA issues fixed (https://issues.jboss.org/):
JWS-1140 - [ASF BZ 62892] tomcat-native memory leak when using Mutual authentication + OCSP
6. References:
https://access.redhat.com/security/cve/CVE-2018-8034 https://access.redhat.com/security/cve/CVE-2018-11784 https://access.redhat.com/security/updates/classification/#moderate
7. Contact:
The Red Hat security contact is <secalert@redhat.com>. More contact details at https://access.redhat.com/security/team/contact/
Copyright 2019 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1
iQIVAwUBXEcdYtzjgjWX9erEAQiB1BAAmNiplBS4OfFnNU/Tlz7Zoy/hx2c1iKIg 8Mi+dtEkraNUuJEBqR6XCbWJjO5gNZ8HzmR6tyunEPdjYM4hJz6oc5mKDm2Cqsyn aa5juvH5pKgXw2KIo8UiV0fnAFmj4El3sahqerbSzpwRCNIJVwtL1zfh2MhQNgn1 TwYseJUPgTHzD2pR2+4+W8extd/Hjn6zsdLGH8otHyDyZcvPV/nfa5VovIMKeHd4 V6UemwYgFp1YU7xfffdkLXzr2c5l6evjy8klVBUb5pjC44FNnCrxQRZm4B/Gt6M/ WiFPDy3PVC5C2P64glCkmG+r5E/IrXYTL32rDmK5tIOkVrFPjyc9e2NmPP1bnJV5 VptpiE6cfIQoEi8ouNxJSd093hMBfaOBYsDoaMAYVk+VrS0W5O2+URPpvXB9PKUP ce8hXekLbe+yXz1UroydUlwZeSB/kKcXBBJp60xXHrVS5N5OSoYZ4TKpAUyxXLZh 9JGqQiCvzdwo46KGkkFJygSv0qGyEZpnCrY4TqAzibJ1XYVXAQ4wwlxoClWi1AnB 4yowBzke2LXJNNGnr9fkFAXVUtIVpKgKeyvo1QUKZfShj4ste5B2DKOiqESxT5Y8 waLBil8JSNALHh1ooeUAPA346vlF5MV6wMQL08YAwwgaXM22r6mURbwAtWWecGRx rxiiJ2FyIyo= =8aLw -----END PGP SIGNATURE-----
-- RHSA-announce mailing list RHSA-announce@redhat.com https://www.redhat.com/mailman/listinfo/rhsa-announce
|
|
|
|