SUSE-SU-2021:3669-1
Not scored
Security update for tomcat
This update for tomcat fixes the following issues: - CVE-2021-30640: Escape parameters in JNDI Realm queries (bsc#1188279). - CVE-2021-33037: Process T-E header from both HTTP 1.0 and HTTP 1.1. clients (bsc#1188278). - CVE-2021-41079: Fixed a denial of service caused by an unexpected TLS packet (bsc#1190558).
Exploit probability
Not scored
Published
November 16, 2021
Required by
Not available
Last source change
February 4, 2026
02 / AFFECTED SOFTWARE
Affected packages
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
Open Source Vulnerabilities
SUSE-SU-2021:3669-1
View original source
This update for tomcat fixes the following issues: - CVE-2021-30640: Escape parameters in JNDI Realm queries (bsc#1188279). - CVE-2021-33037: Process T-E header from both HTTP 1.0 and HTTP 1.1. clients (bsc#1188278). - CVE-2021-41079: Fixed a denial of service caused by an unexpected TLS packet (bsc#1190558).
05 / REFERENCES
Further evidence
- https://bugzilla.suse.com/1188278
- https://bugzilla.suse.com/1188279
- https://bugzilla.suse.com/1190558
- https://www.suse.com/security/cve/CVE-2021-30640
- https://www.suse.com/security/cve/CVE-2021-33037
- https://www.suse.com/security/cve/CVE-2021-41079
- https://www.suse.com/support/update/announcement/2021/suse-su-20213669-1/