[ Все 3 A B C D E F G H I J K L M N O P Q R S T U V W X Y Z ]
×

Проект tomcat-1:9.0.87-2.el9_5.1

Имя tomcat
Эпоха 1
Версия 9.0.87
Релиз 2.el9_5.1
Сайт http://tomcat.apache.org/
Лицензия ASL 2.0
Время сборки 2025-04-08 09:05:17
Хост сборки builder-arm64-1.inferitos.ru
Краткое описание Apache Servlet/JSP Engine, RI for Servlet 4.0/JSP 2.3 API
Репозитории AppStream
Полное описание Tomcat is the servlet container that is used in the official Reference Implementation for the Java Servlet and JavaServer Pages technologies. The Java Servlet and JavaServer Pages specifications are developed by Sun under the Java Community Process. Tomcat is developed in an open and participatory environment and released under the Apache Software License version 2.0. Tomcat is intended to be a collaboration of the best-of-breed developers from around the world.
Эррата INFSA-2025:3645
× Full screenshot
Пакеты link
Пакет Краткое описание Контрольная сумма SHA-256
noarch
tomcat-1:9.0.87-2.el9_5.1.noarch Apache Servlet/JSP Engine, RI for Servlet 4.0/JSP 2.3 API 78c7ee1cdadefe7446b169713b424bcf660f7fb2f8baab8d618b9f6578e81748 download
tomcat-admin-webapps-1:9.0.87-2.el9_5.1.noarch The host-manager and manager web applications for Apache Tomcat 3b659baa90dd5a119bf4bb39bc0dc1d558a2b6d8d6a7ec970ef80dc619fedfe7 download
tomcat-docs-webapp-1:9.0.87-2.el9_5.1.noarch The docs web application for Apache Tomcat 16a326d19ba81d3c997f2260ed30d4bed20b0c2351931355503f909228f2eeb6 download
tomcat-el-3.0-api-1:9.0.87-2.el9_5.1.noarch Apache Tomcat Expression Language v3.0 API Implementation Classes 49c82db1918d967a694828693ac47582000415b853e4241aa00f87b34c2bbf9a download
tomcat-jsp-2.3-api-1:9.0.87-2.el9_5.1.noarch Apache Tomcat JavaServer Pages v2.3 API Implementation Classes 1670ffd3b43a45a8b78b0de7d7870eb925e54c5eeb6fd74e2aaa09e26cc1f0b4 download
tomcat-lib-1:9.0.87-2.el9_5.1.noarch Libraries needed to run the Tomcat Web container cda6aca3d94d14c2898c39161ed1f60d0317cd6c76a9ab4221121b2a42801471 download
tomcat-servlet-4.0-api-1:9.0.87-2.el9_5.1.noarch Apache Tomcat Java Servlet v4.0 API Implementation Classes 3b2e9ca5eb5fc86996a9001922b224af8d821cc7dbf169f0670e9746b0d59d03 download
tomcat-webapps-1:9.0.87-2.el9_5.1.noarch The ROOT web application for Apache Tomcat 4352ad2b238687effbe3ce1a540eb0924cc5c398846177c69a3984125ecd504c download
src
tomcat-1:9.0.87-2.el9_5.1.src Apache Servlet/JSP Engine, RI for Servlet 4.0/JSP 2.3 API 497c8b03a3b16d4c22a988b624add479e57af989191f3adbe2194873edbfdbb3 download
История изменений link
* Wed Apr 02 2025 Adam Krajcik <akrajcik@redhat.com> - 1:9.0.87-2.el9_5.1
- Resolves: RHEL-82946
  tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT (CVE-2025-24813)
- Resolves: RHEL-71719
  tomcat: RCE due to TOCTOU issue in JSP compilation (CVE-2024-50379)

* Thu Aug 08 2024 Adam Krajcik <akrajcik@redhat.com> - 1:9.0.87-2
- Resolves: RHEL-46163
  tomcat: Improper Handling of Exceptional Conditions (CVE-2024-34750)
- Resolves: RHEL-18245 - OpenJDK 21 support for RHEL Tomcat

* Fri May 03 2024 Sokratis Zappis <szappis@redhat.com> - 1:9.0.87-1
- Resolves: RHEL-35812 - Rebase tomcat to version 9.0.87
- Resolves: RHEL-29257
  tomcat: Apache Tomcat: WebSocket DoS with incomplete closing handshake (CVE-2024-23672)
- Resolves: RHEL-29252
  tomcat: : Apache Tomcat: HTTP/2 header handling DoS (CVE-2024-24549)
- Resolves: RHEL-53001 - Amend tomcat's changelog
  (CVE-2023-46589, CVE-2023-45648, CVE-2023-42795, CVE-2023-42794, CVE-2023-44487, CVE-2023-41080)

* Thu Jan 18 2024 Hui Wang <huwang@redhat.com> - 1:9.0.62-39
- Resolves: RHEL-17605
  tomcat: HTTP request smuggling via malformed trailer headers (CVE-2023-46589)

* Thu Nov 23 2023 Hui Wang <huwang@redhat.com> - 1:9.0.62-38
- Resolves: RHEL-13908
  tomcat: incorrectly parsed http trailer headers can cause request smuggling (CVE-2023-45648)
- Resolves: RHEL-13905
  tomcat: improper cleaning of recycled objects could lead to information leak (CVE-2023-42795)
- Resolves: RHEL-12952
  tomcat: FileUpload: DoS due to accumulation of temporary files on Windows (CVE-2023-42794)
- Resolves: RHEL-12552
  tomcat: HTTP/2: Multiple HTTP/2 enabled web servers are vulnerable to a DDoS attack (Rapid Reset Attack) (CVE-2023-44487)
- Resolves: RHEL-2388
  tomcat: Open Redirect vulnerability in FORM authentication (CVE-2023-41080)

* Fri Oct 13 2023 Hui Wang <huwang@redhat.com> - 1:9.0.62-37
- Resolves: RHEL-12551
  tomcat: HTTP/2: Multiple HTTP/2 enabled web servers are vulnerable to a DDoS attack (Rapid Reset Attack) (CVE-2023-44487)
- Remove JDK subpackges which are unused

* Fri Aug 25 2023 Coty Sutherland <csutherl@redhat.com> - 1:9.0.62-16
- Related: #2184133 Declare file conflicts

* Fri Aug 25 2023 Coty Sutherland <csutherl@redhat.com> - 1:9.0.62-15
- Resolves: #2184133 Fix bug in Obsoletes

* Tue Aug 01 2023 Hui Wang <huwang@redhat.com> - 1:9.0.62-14
- Resolves: #2210632 CVE-2023-28709 tomcat

* Wed Jul 26 2023 Hui Wang <huwang@redhat.com> - 1:9.0.62-13
- Resolves: #2189675 Missing Tomcat POM files in RHEL 9.3