Critical Tomcat Vulnerabilities and Important Fixes for Rocky Linux 9 in RLSA-2024:3307
Summary
An update is available for tomcat. This update affects Rocky Linux 9. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list
RPMs
tomcat-1:9.0.87-1.el9_4.1.noarch.rpm
tomcat-1:9.0.87-1.el9_4.1.src.rpm
tomcat-admin-webapps-1:9.0.87-1.el9_4.1.noarch.rpm
tomcat-docs-webapp-1:9.0.87-1.el9_4.1.noarch.rpm
tomcat-el-3.0-api-1:9.0.87-1.el9_4.1.noarch.rpm
tomcat-jsp-2.3-api-1:9.0.87-1.el9_4.1.noarch.rpm
tomcat-lib-1:9.0.87-1.el9_4.1.noarch.rpm
tomcat-servlet-4.0-api-1:9.0.87-1.el9_4.1.noarch.rpm
tomcat-webapps-1:9.0.87-1.el9_4.1.noarch.rpm
References
No References
CVEs
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-23672
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-24549
Fixes
https://bugzilla.redhat.com/show_bug.cgi?id=2269607
https://bugzilla.redhat.com/show_bug.cgi?id=2269608