Alerts This Week
Warning Icon 1 764
Alerts This Week
Warning Icon 1 764

SUSE: 2025:0033-1 important: tomcat10 DoS and RCE Issues

suse
Calendar Grey January 8, 2025
Dist Suse Esm H88
A vital security patch for tomcat10 resolves several severe vulnerabilities affecting SUSE offerings, accompanied by essential advisory details.
* bsc#1233435 * bsc#1234663 * bsc#1234664 Cross-References:

Summary

## This update for tomcat10 fixes the following issues: Update to Tomcat 10.1.34 * Fixed CVEs: * CVE-2024-54677: DoS in examples web application (bsc#1234664) * CVE-2024-50379: RCE due to TOCTOU issue in JSP compilation (bsc#1234663) * CVE-2024-52317: Request/response mix-up with HTTP/2 (bsc#1233435) * Catalina * Add: Add option to serve resources from subpath only with WebDAV Servlet like with DefaultServlet. (michaelo) * Fix: Add special handling for the protocols attribute of SSLHostConfig in storeconfig. (remm) * Fix: 69442: Fix case sensitive check on content-type when parsing request parameters. (remm) * Code: Refactor duplicate code for extracting media type and subtype from content-type into a single method. (markt) * Fix: Compatibility of generated embedded code with components where

References

* bsc#1233435

* bsc#1234663

* bsc#1234664

Cross-

* CVE-2024-50379

* CVE-2024-52317

* CVE-2024-54677

CVSS scores:

* CVE-2024-50379 ( SUSE ): 8.5

CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

* CVE-2024-50379 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

* CVE-2024-50379 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

* CVE-2024-52317 ( SUSE ): 6.9

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N

* CVE-2024-52317 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

* CVE-2024-52317 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

* CVE-2024-54677 ( SUSE ): 8.7

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2025:0033-1
Release Date: 2025-01-07T22:47:30Z
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here