Mageia 2024-0379: tomcat Security Advisory Updates
Summary
Authentication bypass when using Jakarta Authentication API.
(CVE-2024-52316)
Incorrect JSP tag recycling leads to XSS. (CVE-2024-52318)
References
- https://bugs.mageia.org/show_bug.cgi?id=33781
- https://www.openwall.com/lists/oss-security/2024/11/18/2
- https://www.openwall.com/lists/oss-security/2024/11/18/4
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-52316
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-52318
Resolution
MGASA-2024-0379 - Updated tomcat packages fix security vulnerabilities
SRPMS
- 9/core/tomcat-9.0.97-1.mga9
![Dist Mageia](/images/distros/dist-mageia.jpg)