Security update for tomcat
This update for tomcat fixes the following issues: Security issues fixed: - CVE-2022-23181: Fixed time of check, time of use vulnerability that allowed local privilege escalation. (bsc#1195255) - Remove log4j dependency, which is currently directly in use (bsc#1196137) - Make the package RPM conflict even more specific to conflict with java-openjdk-headless >= 9 (bsc#1196091)
02 / AFFECTED SOFTWARE
Affected packages
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
This update for tomcat fixes the following issues: Security issues fixed: - CVE-2022-23181: Fixed time of check, time of use vulnerability that allowed local privilege escalation. (bsc#1195255) - Remove log4j dependency, which is currently directly in use (bsc#1196137) - Make the package RPM conflict even more specific to conflict with java-openjdk-headless >= 9 (bsc#1196091)
05 / REFERENCES