Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

openSUSE-SU-2020:0711-1

Опубликовано: 24 мая 2020
Источник: suse-cvrf

Описание

Security update for tomcat

This update for tomcat fixes the following issues:

  • CVE-2020-9484 (bsc#1171928) Apache Tomcat Remote Code Execution via session persistence

    If an attacker was able to control the contents and name of a file on a server configured to use the PersistenceManager, then the attacker could have triggered a remote code execution via deserialization of the file under their control.

This update was imported from the SUSE:SLE-15-SP1:Update update project.

Список пакетов

openSUSE Leap 15.1
tomcat-9.0.35-lp151.3.18.1
tomcat-admin-webapps-9.0.35-lp151.3.18.1
tomcat-docs-webapp-9.0.35-lp151.3.18.1
tomcat-el-3_0-api-9.0.35-lp151.3.18.1
tomcat-embed-9.0.35-lp151.3.18.1
tomcat-javadoc-9.0.35-lp151.3.18.1
tomcat-jsp-2_3-api-9.0.35-lp151.3.18.1
tomcat-jsvc-9.0.35-lp151.3.18.1
tomcat-lib-9.0.35-lp151.3.18.1
tomcat-servlet-4_0-api-9.0.35-lp151.3.18.1
tomcat-webapps-9.0.35-lp151.3.18.1

Описание

When using Apache Tomcat versions 10.0.0-M1 to 10.0.0-M4, 9.0.0.M1 to 9.0.34, 8.5.0 to 8.5.54 and 7.0.0 to 7.0.103 if a) an attacker is able to control the contents and name of a file on the server; and b) the server is configured to use the PersistenceManager with a FileStore; and c) the PersistenceManager is configured with sessionAttributeValueClassNameFilter="null" (the default unless a SecurityManager is used) or a sufficiently lax filter to allow the attacker provided object to be deserialized; and d) the attacker knows the relative file path from the storage location used by FileStore to the file the attacker has control over; then, using a specifically crafted request, the attacker will be able to trigger remote code execution via deserialization of the file under their control. Note that all of conditions a) to d) must be true for the attack to succeed.


Затронутые продукты
openSUSE Leap 15.1:tomcat-9.0.35-lp151.3.18.1
openSUSE Leap 15.1:tomcat-admin-webapps-9.0.35-lp151.3.18.1
openSUSE Leap 15.1:tomcat-docs-webapp-9.0.35-lp151.3.18.1
openSUSE Leap 15.1:tomcat-el-3_0-api-9.0.35-lp151.3.18.1

Ссылки
Уязвимость openSUSE-SU-2020:0711-1