{"id":"CLSA-2022-1655757814","summary":"Fix CVE(s): CVE-2020-1938, CVE-2020-9484, CVE-2021-25329","details":"\n   * Fix build process:\n     - debian/keystores/*.pem|*.jks: update expiring certs and keystores\n     - debian/patches/0028-update-expiring-test-certs.patch: update expiring\n       test certs\n     - debian/patches/0029-fix-path-to-valid-keystore.patch: fix path to valid\n       keystore\n     - debian/patches/0030-use-tls12-in-tests.patch: use TLSv1.2 protocol\n       instead of TLSv1 for several tests\n   * SECURITY UPDATE: AJP Request Injection and potential Remote Code Execution\n     - debian/patches/CVE-2020-1938-1.patch: rename requiredSecret to secret\n       and add secretRequired\n     - debian/patches/CVE-2020-1938-2.patch: refactor secret check\n     - debian/patches/CVE-2020-1938-3.patch: add new AJP attribute\n       allowedArbitraryRequestAttributes\n     - debian/patches/CVE-2020-1938-4.patch: change the default bind address\n       for AJP to the loopback address\n     - CVE-2020-1938\n   * SECURITY UPDATE: Remote Code Execution via session persistence\n     - debian/patches/CVE-2020-9484.patch: improve validation of storage\n       location when using FileStore\n     - CVE-2020-9484\n   * SECURITY UPDATE: Fix for CVE-2020-9484 was incomplete\n     - debian/patches/CVE-2021-25329.patch: use consistent approach for\n       sub-directory checking\n     - CVE-2021-25329","modified":"2026-06-04T09:45:45.227126070Z","published":"2022-06-20T20:43:34Z","upstream":["CVE-2020-1938","CVE-2020-9484","CVE-2021-25329"],"references":[{"type":"ADVISORY","url":"https://errata.cloudlinux.com/ubuntu16_04/CLSA-2022-1655757814"}],"affected":[{"package":{"name":"libservlet3.0-java","ecosystem":"TuxCare:Ubuntu:16.04","purl":"pkg:deb/tuxcare/libservlet3.0-java?distro=ubuntu-16.04"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"7.0.68-1ubuntu0.4+tuxcare.els1"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/ubuntu16.04els/CLSA-2022-1655757814.json"}},{"package":{"name":"libservlet3.0-java-doc","ecosystem":"TuxCare:Ubuntu:16.04","purl":"pkg:deb/tuxcare/libservlet3.0-java-doc?distro=ubuntu-16.04"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"7.0.68-1ubuntu0.4+tuxcare.els1"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/ubuntu16.04els/CLSA-2022-1655757814.json"}},{"package":{"name":"libtomcat7-java","ecosystem":"TuxCare:Ubuntu:16.04","purl":"pkg:deb/tuxcare/libtomcat7-java?distro=ubuntu-16.04"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"7.0.68-1ubuntu0.4+tuxcare.els1"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/ubuntu16.04els/CLSA-2022-1655757814.json"}},{"package":{"name":"tomcat7","ecosystem":"TuxCare:Ubuntu:16.04","purl":"pkg:deb/tuxcare/tomcat7?distro=ubuntu-16.04"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"7.0.68-1ubuntu0.4+tuxcare.els1"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/ubuntu16.04els/CLSA-2022-1655757814.json"}},{"package":{"name":"tomcat7-admin","ecosystem":"TuxCare:Ubuntu:16.04","purl":"pkg:deb/tuxcare/tomcat7-admin?distro=ubuntu-16.04"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"7.0.68-1ubuntu0.4+tuxcare.els1"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/ubuntu16.04els/CLSA-2022-1655757814.json"}},{"package":{"name":"tomcat7-common","ecosystem":"TuxCare:Ubuntu:16.04","purl":"pkg:deb/tuxcare/tomcat7-common?distro=ubuntu-16.04"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"7.0.68-1ubuntu0.4+tuxcare.els1"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/ubuntu16.04els/CLSA-2022-1655757814.json"}},{"package":{"name":"tomcat7-docs","ecosystem":"TuxCare:Ubuntu:16.04","purl":"pkg:deb/tuxcare/tomcat7-docs?distro=ubuntu-16.04"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"7.0.68-1ubuntu0.4+tuxcare.els1"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/ubuntu16.04els/CLSA-2022-1655757814.json"}},{"package":{"name":"tomcat7-examples","ecosystem":"TuxCare:Ubuntu:16.04","purl":"pkg:deb/tuxcare/tomcat7-examples?distro=ubuntu-16.04"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"7.0.68-1ubuntu0.4+tuxcare.els1"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/ubuntu16.04els/CLSA-2022-1655757814.json"}},{"package":{"name":"tomcat7-user","ecosystem":"TuxCare:Ubuntu:16.04","purl":"pkg:deb/tuxcare/tomcat7-user?distro=ubuntu-16.04"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"7.0.68-1ubuntu0.4+tuxcare.els1"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/ubuntu16.04els/CLSA-2022-1655757814.json"}}],"schema_version":"1.7.5"}