Lucene search

K
oraclelinuxOracleLinuxELSA-2024-3666
HistoryJun 06, 2024 - 12:00 a.m.

tomcat security and bug fix update

2024-06-0600:00:00
linux.oracle.com
4
tomcat 9.0.87
security
bug fix
update
cve-2024-23672
cve-2024-24549
websocket dos
http/2 header dos

6.8 Medium

AI Score

Confidence

Low

0.0004 Low

EPSS

Percentile

10.5%

[1:9.0.87-1.el8_10.1]

  • Resolves: RHEL-38548 - Amend tomcat package’s changelog so that fixed CVEs are mentioned explicitly
  • Resolves: RHEL-35813 - Rebase tomcat to version 9.0.87
  • Resolves: RHEL-29255
    tomcat: Apache Tomcat: WebSocket DoS with incomplete closing handshake (CVE-2024-23672)
  • Resolves: RHEL-29250
    tomcat: Apache Tomcat: HTTP/2 header handling DoS (CVE-2024-24549)