Описание
Security update for tomcat
This update for tomcat fixes the following issues:
- CVE-2023-28708: Fixed information disclosure by not including the secure attribute (bsc#1209622).
Список пакетов
SUSE Linux Enterprise High Performance Computing 15 SP1-LTSS
tomcat-9.0.36-150100.4.90.1
tomcat-admin-webapps-9.0.36-150100.4.90.1
tomcat-el-3_0-api-9.0.36-150100.4.90.1
tomcat-jsp-2_3-api-9.0.36-150100.4.90.1
tomcat-lib-9.0.36-150100.4.90.1
tomcat-servlet-4_0-api-9.0.36-150100.4.90.1
tomcat-webapps-9.0.36-150100.4.90.1
SUSE Linux Enterprise Server 15 SP1-LTSS
tomcat-9.0.36-150100.4.90.1
tomcat-admin-webapps-9.0.36-150100.4.90.1
tomcat-el-3_0-api-9.0.36-150100.4.90.1
tomcat-jsp-2_3-api-9.0.36-150100.4.90.1
tomcat-lib-9.0.36-150100.4.90.1
tomcat-servlet-4_0-api-9.0.36-150100.4.90.1
tomcat-webapps-9.0.36-150100.4.90.1
SUSE Linux Enterprise Server for SAP Applications 15 SP1
tomcat-9.0.36-150100.4.90.1
tomcat-admin-webapps-9.0.36-150100.4.90.1
tomcat-el-3_0-api-9.0.36-150100.4.90.1
tomcat-jsp-2_3-api-9.0.36-150100.4.90.1
tomcat-lib-9.0.36-150100.4.90.1
tomcat-servlet-4_0-api-9.0.36-150100.4.90.1
tomcat-webapps-9.0.36-150100.4.90.1
Ссылки
- Link for SUSE-SU-2023:1669-1
- E-Mail link for SUSE-SU-2023:1669-1
- SUSE Security Ratings
- SUSE Bug 1209622
- SUSE CVE CVE-2023-28708 page
Описание
When using the RemoteIpFilter with requests received from a reverse proxy via HTTP that include the X-Forwarded-Proto header set to https, session cookies created by Apache Tomcat 11.0.0-M1 to 11.0.0.-M2, 10.1.0-M1 to 10.1.5, 9.0.0-M1 to 9.0.71 and 8.5.0 to 8.5.85 did not include the secure attribute. This could result in the user agent transmitting the session cookie over an insecure channel.
Затронутые продукты
SUSE Linux Enterprise High Performance Computing 15 SP1-LTSS:tomcat-9.0.36-150100.4.90.1
SUSE Linux Enterprise High Performance Computing 15 SP1-LTSS:tomcat-admin-webapps-9.0.36-150100.4.90.1
SUSE Linux Enterprise High Performance Computing 15 SP1-LTSS:tomcat-el-3_0-api-9.0.36-150100.4.90.1
SUSE Linux Enterprise High Performance Computing 15 SP1-LTSS:tomcat-jsp-2_3-api-9.0.36-150100.4.90.1
Ссылки
- CVE-2023-28708
- SUSE Bug 1209622