SUSE-SU-2021:1009-1
Not scored
Security update for tomcat
This update for tomcat fixes the following issues: - CVE-2021-24122: Fixed an information disclosure if resources are served from the NTFS file system (bsc#1180947). - CVE-2021-25122: Apache Tomcat h2c request mix-up (bsc#1182912) - CVE-2021-25329: Complete fix for CVE-2020-9484 (bsc#1182909)
Exploit probability
Not scored
Published
April 1, 2021
Required by
Not available
Last source change
February 4, 2026
02 / AFFECTED SOFTWARE
Affected packages
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
Open Source Vulnerabilities
SUSE-SU-2021:1009-1
View original source
This update for tomcat fixes the following issues: - CVE-2021-24122: Fixed an information disclosure if resources are served from the NTFS file system (bsc#1180947). - CVE-2021-25122: Apache Tomcat h2c request mix-up (bsc#1182912) - CVE-2021-25329: Complete fix for CVE-2020-9484 (bsc#1182909)
05 / REFERENCES
Further evidence
- https://bugzilla.suse.com/1180947
- https://bugzilla.suse.com/1182909
- https://bugzilla.suse.com/1182912
- https://www.suse.com/security/cve/CVE-2021-24122
- https://www.suse.com/security/cve/CVE-2021-25122
- https://www.suse.com/security/cve/CVE-2021-25329
- https://www.suse.com/support/update/announcement/2021/suse-su-20211009-1/