VYPR

rpm package

almalinux/tomcat-el-3.0-api

pkg:rpm/almalinux/tomcat-el-3.0-api

Vulnerabilities (25)

  • CVE-2023-44487HigKEVOct 10, 2023
    affected < 1:9.0.62-5.el8_8.2fixed 1:9.0.62-5.el8_8.2

    The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.

  • CVE-2023-41080Aug 25, 2023
    affected < 1:9.0.62-27.el8_9.2fixed 1:9.0.62-27.el8_9.2

    URL Redirection to Untrusted Site ('Open Redirect') vulnerability in FORM authentication feature Apache Tomcat.This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.0-M10, from 10.1.0-M1 through 10.0.12, from 9.0.0-M1 through 9.0.79 and from 8.5.0 through 8.5.92. Older, E

  • CVE-2023-28709May 22, 2023
    affected < 1:9.0.62-37.el9_3fixed 1:9.0.62-37.el9_3

    The fix for CVE-2023-24998 was incomplete for Apache Tomcat 11.0.0-M2 to 11.0.0-M4, 10.1.5 to 10.1.7, 9.0.71 to 9.0.73 and 8.5.85 to 8.5.87. If non-default HTTP connector settings were used such that the maxParameterCount could be reached using query string parameters and a

  • CVE-2023-28708Mar 22, 2023
    affected < 1:9.0.62-37.el9_3fixed 1:9.0.62-37.el9_3

    When using the RemoteIpFilter with requests received from a reverse proxy via HTTP that include the X-Forwarded-Proto header set to https, session cookies created by Apache Tomcat 11.0.0-M1 to 11.0.0.-M2, 10.1.0-M1 to 10.1.5, 9.0.0-M1 to 9.0.71 and 8.5.0 to 8.5.85 did not i

  • CVE-2023-24998Feb 20, 2023
    affected < 1:9.0.62-37.el9_3fixed 1:9.0.62-37.el9_3

    Apache Commons FileUpload before 1.5 does not limit the number of request parts to be processed resulting in the possibility of an attacker triggering a DoS with a malicious upload or series of uploads. Note that, like all of the file upload limits, the new configur

Page 2 of 2