Bug 1934061 (CVE-2021-25329)
| Summary: | CVE-2021-25329 tomcat: Incomplete fix for CVE-2020-9484 (RCE via session persistence) | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | Ted Jongseok Won <jwon> |
| Component: | vulnerability | Assignee: | Red Hat Product Security <security-response-team> |
| Status: | CLOSED ERRATA | QA Contact: | |
| Severity: | low | Docs Contact: | |
| Priority: | low | ||
| Version: | unspecified | CC: | aileenc, akoufoud, alazarot, alee, almorale, anstephe, asoldano, atangrin, avibelli, bbaranow, bgeorges, bmaxwell, brian.stansberry, cdewolf, chazlett, cmoulliard, coolsvap, csutherl, darran.lofthouse, dhanak, dkreling, dosoudil, drieden, drosa, dsoumis, eglynn, eleandro, etirelli, fjuma, ggaughan, gmalinko, gzaronik, huwang, ibek, ikanello, ivan.afonichev, iweiss, janstey, java-sig-commits, jclere, jjoyce, jochrist, jolee, jpallich, jperkins, jpretori, jrokos, jschatte, jschluet, jstastny, jwon, krathod, krzysztof.daniel, kverlaen, kwills, lgao, lhh, lpeer, lthon, mburns, mgarciac, mkolesni, mnovotny, msochure, msvehla, mszynkie, nwallace, pdelbell, pgallagh, pjindal, plodge, pmackay, rguimara, rhcs-maint, rhel-process-autobot, rmaucher, rrajasek, rruss, rstancel, rstepani, rsvoboda, rsynek, sausingh, sclewis, scohen, sdaley, slinaber, smaestri, szappis, tom.jenkinson, watson-tool-maintainers, yborgess, ytale |
| Target Milestone: | --- | Keywords: | Security |
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | tomcat 10.0.2, tomcat 9.0.43, tomcat 8.5.63, tomcat 7.0.108 | Doc Type: | If docs needed, set a value |
| Doc Text: | Story Points: | --- | |
| Clone Of: | Environment: | ||
| Last Closed: | 2021-06-29 10:40:45 UTC | Type: | --- |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
| Bug Depends On: | 1942663 | ||
| Bug Blocks: | 1934010 | ||
|
Description
Ted Jongseok Won
2021-03-02 12:09:58 UTC
External References: http://mail-archives.apache.org/mod_mbox/tomcat-announce/202103.mbox/%3C811bba77-e74e-9f9b-62ca-5253a09ba84f%40apache.org%3E https://tomcat.apache.org/security-10.html#Fixed_in_Apache_Tomcat_10.0.2 https://tomcat.apache.org/security-9.html#Fixed_in_Apache_Tomcat_9.0.43 https://tomcat.apache.org/security-8.html#Fixed_in_Apache_Tomcat_8.5.63 https://tomcat.apache.org/security-7.html#Fixed_in_Apache_Tomcat_7.0.108 Statement: In Red Hat Enterprise Linux 8, Red Hat Certificate System 10 and Identity Management are using the `pki-servlet-engine` component, which embeds a vulnerable version of Tomcat. However, in these specific contexts, the prerequisites to the vulnerability are not met. The PersistentManager is not set, and a SecurityManager is used. The use of `pki-servlet-engine` outside of these contexts is not supported. As a result, the vulnerability can not be triggered in supported configurations of these products. Red Hat OpenStack Platform's OpenDaylight will not be updated for this flaw because it was deprecated as of OpenStack Platform 14 and is only receiving security fixes for Important and Critical flaws. This issue has been addressed in the following products: Red Hat JBoss Web Server Via RHSA-2021:2562 https://access.redhat.com/errata/RHSA-2021:2562 This issue has been addressed in the following products: Red Hat JBoss Web Server 5.5 on RHEL 7 Red Hat JBoss Web Server 5.5 on RHEL 8 Via RHSA-2021:2561 https://access.redhat.com/errata/RHSA-2021:2561 This bug is now closed. Further updates for individual products will be reflected on the CVE page(s): https://access.redhat.com/security/cve/cve-2021-25329 This issue has been addressed in the following products: Red Hat support for Spring Boot 2.3.10 Via RHSA-2021:3425 https://access.redhat.com/errata/RHSA-2021:3425 This issue has been addressed in the following products: Red Hat Fuse 7.11 Via RHSA-2022:5532 https://access.redhat.com/errata/RHSA-2022:5532 |