Lucene search

K
redhatRedHatRHSA-2020:4004
HistorySep 29, 2020 - 7:50 a.m.

(RHSA-2020:4004) Important: tomcat security and bug fix update

2020-09-2907:50:50
access.redhat.com
142

0.148 Low

EPSS

Percentile

95.8%

Apache Tomcat is a servlet container for the Java Servlet and JavaServer Pages (JSP) technologies.

Security Fix(es):

  • tomcat: multiple requests with invalid payload length in a WebSocket frame could lead to DoS (CVE-2020-13935)

  • tomcat: session fixation when using FORM authentication (CVE-2019-17563)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Additional Changes:

For detailed information on changes in this release, see the Red Hat Enterprise Linux 7.9 Release Notes linked from the References section.