SUSE-SU-2021:0989-1
Not scored
Security update for tomcat
This update for tomcat fixes the following issues: - Fixed CVEs: * CVE-2021-25122: Apache Tomcat h2c request mix-up (bsc#1182912) * CVE-2021-25329: Complete fix for CVE-2020-9484 (bsc#1182909) - Log if file access is blocked due to symlinks: CVE-2021-24122 (bsc#1180947)
Exploit probability
Not scored
Published
March 30, 2021
Required by
Not available
Last source change
May 2, 2025
02 / AFFECTED SOFTWARE
Affected packages
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
Open Source Vulnerabilities
SUSE-SU-2021:0989-1
View original source
This update for tomcat fixes the following issues: - Fixed CVEs: * CVE-2021-25122: Apache Tomcat h2c request mix-up (bsc#1182912) * CVE-2021-25329: Complete fix for CVE-2020-9484 (bsc#1182909) - Log if file access is blocked due to symlinks: CVE-2021-24122 (bsc#1180947)
05 / REFERENCES
Further evidence
- https://bugzilla.suse.com/1180947
- https://bugzilla.suse.com/1182909
- https://bugzilla.suse.com/1182912
- https://www.suse.com/security/cve/CVE-2021-24122
- https://www.suse.com/security/cve/CVE-2021-25122
- https://www.suse.com/security/cve/CVE-2021-25329
- https://www.suse.com/support/update/announcement/2021/suse-su-20210989-1/