For details on how to apply this update, which includes the changes
described in this advisory, refer to:
https://access.redhat.com/articles/11258
The Public Key Infrastructure (PKI) Deps module contains fundamental
packages required as dependencies for the pki-core module by Red Hat
Certificate System.
Security Fix(es):
* tomcat: Due to a mishandling of close in NIO/NIO2 connectors user
sessions can get mixed up (CVE-2018-8037)
* tomcat: Insecure defaults in CORS filter enable 'supportsCredentials' for
all origins (CVE-2018-8014)
* tomcat: Open redirect in default servlet (CVE-2018-11784)
* tomcat: Host name verification missing in WebSocket client
(CVE-2018-8034)
For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE
page(s) listed in the References section.
https://access.redhat.com/security/cve/CVE-2018-8014 https://access.redhat.com/security/cve/CVE-2018-8034 https://access.redhat.com/security/cve/CVE-2018-8037 https://access.redhat.com/security/cve/CVE-2018-11784 https://access.redhat.com/security/updates/classification/#important
Red Hat Enterprise Linux AppStream (v. 8):
Source:
apache-commons-collections-3.2.2-10.module+el8.0.0+3248+9d514f3b.src.rpm
apache-commons-lang-2.6-21.module+el8.0.0+3248+9d514f3b.src.rpm
bea-stax-1.2.0-16.module+el8.0.0+3248+9d514f3b.src.rpm
glassfish-fastinfoset-1.2.13-9.module+el8.0.0+3248+9d514f3b.src.rpm
glassfish-jaxb-2.2.11-11.module+el8.0.0+3248+9d514f3b.src.rpm
glassfish-jaxb-api-2.2.12-8.module+el8.0.0+3248+9d514f3b.src.rpm
jackson-annotations-2.9.8-1.module+el8.0.0+3248+9d514f3b.src.rpm
jackson-core-2.9.8-1.module+el8.0.0+3248+9d514f3b.src.rpm
jackson-databind-2.9.8-1.module+el8.0.0+3248+9d514f3b.src.rpm
jackson-jaxrs-providers-2.9.8-1.module+el8.0.0+3248+9d514f3b.src.rpm
jackson-module-jaxb-annotations-2.7.6-4.module+el8.0.0+3248+9d514f3b.src.rpm
jakarta-commons-httpclient-3.1-28.module+el8.0.0+3248+9d514f3b.src.rpm
javassist-3.18.1-8.module+el8.0.0+3248+9d514f3b.src.rpm
pki-servlet-container-9.0.7-14.module+el8.0.0+3248+9d514f3b.src.rpm
python-nss-1.0.1-10.module+el8.0.0+3248+9d514f3b.src.rpm
relaxngDatatype-2011.1-7.module+el8.0.0+3248+9d514f3b.src.rpm
resteasy-3.0.26-3.module+el8.0.0+3248+9d514f3b.src.rpm
slf4j-1.7.25-4.module+el8.0.0+3248+9d514f3b.src.rpm
stax-ex-1.7.7-8.module+el8.0.0+3248+9d514f3b.src.rpm
Read the Full Advisory
An update for the pki-deps:10.6 module is now available for Red HatEnterprise Linux 8.Red Hat Product Security has rated this update as having a security impactof Important. A Common Vulnerability Scoring System (CVSS) base score,which gives a detailed severity rating, is available for each vulnerabilityfrom the CVE link(s) in the References section.
Red Hat Enterprise Linux AppStream (v. 8) - aarch64, noarch, ppc64le, s390x, x86_64
1579611 - CVE-2018-8014 tomcat: Insecure defaults in CORS filter enable 'supportsCredentials' for all origins
1607580 - CVE-2018-8034 tomcat: Host name verification missing in WebSocket client
1607582 - CVE-2018-8037 tomcat: Due to a mishandling of close in NIO/NIO2 connectors user sessions can get mixed up
1636512 - CVE-2018-11784 tomcat: Open redirect in default servlet
Get the latest Linux and open source security news straight to your inbox.