Fedora 28 : 1:tomcat (2018-b1832101b8)
High Nessus Plugin ID 120717
SynopsisThe remote Fedora host is missing a security update.
DescriptionThis update includes a rebase from 8.5.30 up to 8.5.32 which resolves two CVEs along with various other bugs/features :
- rhbz#1579612 CVE-2018-8014 tomcat: Insecure defaults in CORS filter enable 'supportsCredentials' for all origins
- rhbz#1607586 CVE-2018-8034 tomcat: host name verification missing in WebSocket client
- rhbz#1607584 CVE-2018-8037 tomcat: Due to a mishandling of close in NIO/NIO2 connectors user sessions can get mixed up
Note that Tenable Network Security has extracted the preceding description block directly from the Fedora update system website.
Tenable has attempted to automatically clean and format it as much as possible without introducing additional issues.
SolutionUpdate the affected 1:tomcat package.