Security update for tomcat
This update for tomcat fixes the following issues: - CVE-2023-42795: Fixed a potential information leak due to insufficient cleanup (bsc#1216119). - CVE-2023-45648: Fixed a request smuggling issue due to an incorrect parsing of HTTP trailer headers (bsc#1216118). - CVE-2023-41080: Fixed URL Redirection to Untrusted Site ('Open Redirect') vulnerability in FORM authentication feature (bsc#1214666).
02 / AFFECTED SOFTWARE
Affected packages
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
This update for tomcat fixes the following issues: - CVE-2023-42795: Fixed a potential information leak due to insufficient cleanup (bsc#1216119). - CVE-2023-45648: Fixed a request smuggling issue due to an incorrect parsing of HTTP trailer headers (bsc#1216118). - CVE-2023-41080: Fixed URL Redirection to Untrusted Site ('Open Redirect') vulnerability in FORM authentication feature (bsc#1214666).
05 / REFERENCES
Further evidence
- https://bugzilla.suse.com/1214666
- https://bugzilla.suse.com/1216118
- https://bugzilla.suse.com/1216119
- https://www.suse.com/security/cve/CVE-2023-41080
- https://www.suse.com/security/cve/CVE-2023-42795
- https://www.suse.com/security/cve/CVE-2023-45648
- https://www.suse.com/support/update/announcement/2023/suse-su-20234423-1/