Apache Tomcat versions 7.0.0 to 7.0.84, 8.0.0.RC1 to 8.0.49 and 8.5.0 to 8.5.27 does not properly handle the URL empty string ("") when used as part of a security constraint definition. This can lead to the security constraint being ignored, leading to unitended exposure of resources. External References: https://tomcat.apache.org/security-7.html#Fixed_in_Apache_Tomcat_7.0.85 https://tomcat.apache.org/security-8.html#Fixed_in_Apache_Tomcat_8.0.50 https://tomcat.apache.org/security-8.html#Fixed_in_Apache_Tomcat_8.5.28 Upstream Bug Report: https://bz.apache.org/bugzilla/show_bug.cgi?id=62067 Upstream Fixes: Tomcat 7.0.x: http://svn.apache.org/viewvc?view=rev&rev=1823309 Tomcat 8.0.x: http://svn.apache.org/viewvc?view=rev&rev=1814827 Tomcat 8.5.x: http://svn.apache.org/viewvc?view=rev&rev=1823307
Created tomcat tracking bugs for this issue: Affects: epel-all [bug 1548291] Affects: fedora-all [bug 1548290]
Created tomcat tracking bugs for this issue: Affects: fedora-all [bug 1550285] Affects: epel-all [bug 1550287]
This issue has been addressed in the following products: Red Hat JBoss Web Server Via RHSA-2018:0465 https://access.redhat.com/errata/RHSA-2018:0465
This issue has been addressed in the following products: Red Hat JBoss Web Server 3 for RHEL 6 Red Hat JBoss Web Server 3 for RHEL 7 Via RHSA-2018:0466 https://access.redhat.com/errata/RHSA-2018:0466
JBoss EAP 6.x, which includes jbossweb component is no longer included in Openshift Online. Marking as not affected.
This issue has been addressed in the following products: Red Hat Openshift Application Runtimes Via RHSA-2018:1320 https://access.redhat.com/errata/RHSA-2018:1320
This issue has been addressed in the following products: Red Hat JBoss Enterprise Application Platform Via RHSA-2018:1447 https://access.redhat.com/errata/RHSA-2018:1447
This issue has been addressed in the following products: Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7 Via RHSA-2018:1448 https://access.redhat.com/errata/RHSA-2018:1448
This issue has been addressed in the following products: Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6 Via RHSA-2018:1449 https://access.redhat.com/errata/RHSA-2018:1449
This issue has been addressed in the following products: Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 5 Via RHSA-2018:1450 https://access.redhat.com/errata/RHSA-2018:1450
This issue has been addressed in the following products: Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6 Via RHSA-2018:1451 https://access.redhat.com/errata/RHSA-2018:1451
This issue has been addressed in the following products: Red Hat Fuse Intergration Services 2.0 based on Fuse 6.3 R8 Via RHSA-2018:2939 https://access.redhat.com/errata/RHSA-2018:2939
This issue has been addressed in the following products: Red Hat Enterprise Linux 7 Via RHSA-2019:2205 https://access.redhat.com/errata/RHSA-2019:2205