Oval Definition:oval:com.redhat.rhsa:def:20191529
Revision Date:2019-06-18Version:635
Title:RHSA-2019:1529: pki-deps:10.6 security update (Important)
Description:The Public Key Infrastructure (PKI) Deps module contains fundamental packages required as dependencies for the pki-core module by Red Hat Certificate System.

Security Fix(es):

  • tomcat: Due to a mishandling of close in NIO/NIO2 connectors user sessions can get mixed up (CVE-2018-8037)

  • tomcat: Insecure defaults in CORS filter enable 'supportsCredentials' for all origins (CVE-2018-8014)

  • tomcat: Open redirect in default servlet (CVE-2018-11784)

  • tomcat: Host name verification missing in WebSocket client (CVE-2018-8034)

    For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
  • Family:unixClass:patch
    Status:Reference(s):CVE-2018-11784
    CVE-2018-8014
    CVE-2018-8034
    CVE-2018-8037
    RHSA-2019:1529
    Platform(s):Red Hat Enterprise Linux 8
    Product(s):
    Definition Synopsis
  • Red Hat Enterprise Linux must be installed
  • OR Package Information
  • Red Hat Enterprise Linux 8 is installed
  • OR Red Hat CoreOS 4 is installed
  • AND
  • Module pki-deps:10.6 is enabled
  • BACK