MGASA-2024-0379 - Updated tomcat packages fix security vulnerabilities

Publication date: 27 Nov 2024
URL: https://advisories.mageia.org/MGASA-2024-0379.html
Type: security
Affected Mageia releases: 9
CVE: CVE-2024-52316,
     CVE-2024-52318

Authentication bypass when using Jakarta Authentication API.
(CVE-2024-52316)
Incorrect JSP tag recycling leads to XSS. (CVE-2024-52318)

References:
- https://bugs.mageia.org/show_bug.cgi?id=33781
- https://www.openwall.com/lists/oss-security/2024/11/18/2
- https://www.openwall.com/lists/oss-security/2024/11/18/4
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-52316
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-52318

SRPMS:
- 9/core/tomcat-9.0.97-1.mga9

Mageia 2024-0379: tomcat Security Advisory Updates

Authentication bypass when using Jakarta Authentication API

Summary

Authentication bypass when using Jakarta Authentication API. (CVE-2024-52316) Incorrect JSP tag recycling leads to XSS. (CVE-2024-52318)

References

- https://bugs.mageia.org/show_bug.cgi?id=33781

- https://www.openwall.com/lists/oss-security/2024/11/18/2

- https://www.openwall.com/lists/oss-security/2024/11/18/4

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-52316

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-52318

Resolution

MGASA-2024-0379 - Updated tomcat packages fix security vulnerabilities

SRPMS

- 9/core/tomcat-9.0.97-1.mga9

Severity
Publication date: 27 Nov 2024
URL: https://advisories.mageia.org/MGASA-2024-0379.html
Type: security
CVE: CVE-2024-52316, CVE-2024-52318

Related News