Bug 1403824 (CVE-2016-8745)
Summary: | CVE-2016-8745 tomcat: information disclosure due to incorrect Processor sharing | ||
---|---|---|---|
Product: | [Other] Security Response | Reporter: | Martin Prpič <mprpic> |
Component: | vulnerability | Assignee: | Red Hat Product Security <security-response-team> |
Status: | CLOSED ERRATA | QA Contact: | |
Severity: | high | Docs Contact: | |
Priority: | high | ||
Version: | unspecified | CC: | aileenc, alazarot, alee, aszczucz, bbaranow, bmaxwell, ccoleman, cdewolf, chazlett, coolsvap, csutherl, dandread, darran.lofthouse, dedgar, dimitris, dmcphers, dosoudil, etirelli, fgavrilo, fnasser, gvarsami, gzaronik, huwang, ivan.afonichev, jason.greene, java-sig-commits, jawilson, jboss-set, jclere, jcoleman, jdg-bugs, jdoyle, jgoulding, jialiu, jokerman, jolee, jondruse, jshepherd, kbost, kconner, krzysztof.daniel, kverlaen, ldimaggi, lgao, lmeyer, loleary, lpetrovi, mbabacek, mbaluch, miburman, mmccomas, mprpic, mwinkler, myarboro, nwallace, pgier, pjurak, ppalaga, psakar, pslavice, rdovell, rnetuka, rrajasek, rstancel, rsvoboda, rwagner, rzhang, soa-p-jira, spinder, tcunning, theute, tkirby, ttarrant, twalsh, vhalbert, vtunka, weli, yozone |
Target Milestone: | --- | Keywords: | Security |
Target Release: | --- | ||
Hardware: | All | ||
OS: | Linux | ||
Whiteboard: | |||
Fixed In Version: | tomcat 8.5.9, tomcat 9.0.0.M15, tomcat 6.0.50, tomcat 7.0.75, tomcat 8.0.41 | Doc Type: | If docs needed, set a value |
Doc Text: |
A bug was discovered in the error handling of the send file code for the NIO HTTP connector. This led to the current Processor object being added to the Processor cache multiple times allowing information leakage between requests including, and not limited to, session ID and the response body.
|
Story Points: | --- |
Clone Of: | Environment: | ||
Last Closed: | 2019-06-08 03:04:10 UTC | Type: | --- |
Regression: | --- | Mount Type: | --- |
Documentation: | --- | CRM: | |
Verified Versions: | Category: | --- | |
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
Cloudforms Team: | --- | Target Upstream Version: | |
Embargoed: | |||
Bug Depends On: | 1403825, 1413588, 1413589, 1413591, 1413592, 1424820, 1470474 | ||
Bug Blocks: | 1403827, 1428325 |
Description
Martin Prpič
2016-12-12 12:42:45 UTC
Created tomcat tracking bugs for this issue: Affects: fedora-all [bug 1403825] External References: https://tomcat.apache.org/security-8.html#Fixed_in_Apache_Tomcat_8.5.9 https://tomcat.apache.org/security-8.html#Fixed_in_Apache_Tomcat_8.0.40 https://tomcat.apache.org/security-7.html#Fixed_in_Apache_Tomcat_7.0.74 https://tomcat.apache.org/security-6.html#Fixed_in_Apache_Tomcat_6.0.49 I've submitted an update for this on epel-6 already just a moment ago. I guess we should file a bug for it and add it to the update? Created tomcat tracking bugs for this issue: Affects: epel-6 [bug 1424820] (In reply to Coty Sutherland from comment #7) > I've submitted an update for this on epel-6 already just a moment ago. I > guess we should file a bug for it and add it to the update? Done, please use bug 1424820. This issue has been addressed in the following products: Red Hat JBoss Web Server 3.1.0 Via RHSA-2017:0457 https://rhn.redhat.com/errata/RHSA-2017-0457.html This issue has been addressed in the following products: Red Hat JBoss Web Server 3 for RHEL 7 Via RHSA-2017:0456 https://access.redhat.com/errata/RHSA-2017:0456 This issue has been addressed in the following products: Red Hat JBoss Web Server 3 for RHEL 6 Via RHSA-2017:0455 https://access.redhat.com/errata/RHSA-2017:0455 This issue has been addressed in the following products: Red Hat Enterprise Linux 6 Via RHSA-2017:0527 https://rhn.redhat.com/errata/RHSA-2017-0527.html This issue has been addressed in the following products: Red Hat Enterprise Linux 7 Via RHSA-2017:0935 https://access.redhat.com/errata/RHSA-2017:0935 Created jbossweb tracking bugs for this issue: Affects: openshift-1 [bug 1470474] |