Rocky Linux 8 : tomcat (RLSA-2024:3666)
Discription

The remote Rocky Linux 8 host has packages installed that are affected by multiple vulnerabilities as referenced in the RLSA-2024:3666 advisory. * Apache Tomcat: HTTP/2 header handling DoS (CVE-2024-24549) * Apache Tomcat: WebSocket DoS with incomplete closing handshake (CVE-2024-23672) Bug Fix(es): * Rebase tomcat to version 9.0.87 (JIRA:Rocky Linux-35813) * Amend tomcat package's changelog so that fixed CVEs are mentioned explicitly (JIRA:Rocky Linux-38548) Tenable has extracted the preceding description block directly from the Rocky Linux security advisory. Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version…Read More

Back to Main

Subscribe for the latest news: