Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

rocky логотип

RLSA-2019:1529

Опубликовано: 18 июн. 2019
Источник: rocky
Оценка: Important

Описание

Important: pki-deps:10.6 security update

The Public Key Infrastructure (PKI) Deps module contains fundamental packages required as dependencies for the pki-core module by Rocky Enterprise Software Foundation Certificate System.

Security Fix(es):

  • tomcat: Due to a mishandling of close in NIO/NIO2 connectors user sessions can get mixed up (CVE-2018-8037)

  • tomcat: Insecure defaults in CORS filter enable 'supportsCredentials' for all origins (CVE-2018-8014)

  • tomcat: Open redirect in default servlet (CVE-2018-11784)

  • tomcat: Host name verification missing in WebSocket client (CVE-2018-8034)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Затронутые продукты

  • Rocky Linux 8

НаименованиеАрхитектураРелизRPM
apache-commons-collectionsnoarch10.module+el8.3.0+53+ea062990apache-commons-collections-3.2.2-10.module+el8.3.0+53+ea062990.noarch.rpm
apache-commons-langnoarch21.module+el8.3.0+53+ea062990apache-commons-lang-2.6-21.module+el8.3.0+53+ea062990.noarch.rpm
bea-stax-apinoarch16.module+el8.3.0+53+ea062990bea-stax-api-1.2.0-16.module+el8.3.0+53+ea062990.noarch.rpm
glassfish-fastinfosetnoarch9.module+el8.3.0+53+ea062990glassfish-fastinfoset-1.2.13-9.module+el8.3.0+53+ea062990.noarch.rpm
glassfish-jaxb-apinoarch8.module+el8.3.0+53+ea062990glassfish-jaxb-api-2.2.12-8.module+el8.3.0+53+ea062990.noarch.rpm
glassfish-jaxb-corenoarch11.module+el8.3.0+53+ea062990glassfish-jaxb-core-2.2.11-11.module+el8.3.0+53+ea062990.noarch.rpm
glassfish-jaxb-runtimenoarch11.module+el8.3.0+53+ea062990glassfish-jaxb-runtime-2.2.11-11.module+el8.3.0+53+ea062990.noarch.rpm
glassfish-jaxb-txw2noarch11.module+el8.3.0+53+ea062990glassfish-jaxb-txw2-2.2.11-11.module+el8.3.0+53+ea062990.noarch.rpm
jackson-module-jaxb-annotationsnoarch4.module+el8.3.0+53+ea062990jackson-module-jaxb-annotations-2.7.6-4.module+el8.3.0+53+ea062990.noarch.rpm
jakarta-commons-httpclientnoarch28.module+el8.3.0+53+ea062990jakarta-commons-httpclient-3.1-28.module+el8.3.0+53+ea062990.noarch.rpm

Показывать по

Связанные уязвимости

oracle-oval
почти 6 лет назад

ELSA-2019-1529: pki-deps:10.6 security update (IMPORTANT)

suse-cvrf
больше 6 лет назад

Security update for tomcat

suse-cvrf
больше 6 лет назад

Security update for tomcat

suse-cvrf
больше 6 лет назад

Security update for tomcat

suse-cvrf
почти 7 лет назад

Security update for tomcat