Description of problem: https://www.tenable.com/blog/cve-2020-1938-ghostcat-apache-tomcat-ajp-file-readinclusion-vulnerability-cnvd-2020-10487 Version-Release number of selected component (if applicable): all current versions
I'm marking this as a duplicate of the fedora tracker for CVE-2020-1938. There's already an update in progress to resolve this, see https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2020-81c37f8ff5. In the meantime, you don't have to wait for an update to protect mitigate this vulnerability. Please review the guidance provided in https://access.redhat.com/security/cve/CVE-2020-1938 and https://access.redhat.com/solutions/4851251 as soon as you can and update your configurations accordingly. *** This bug has been marked as a duplicate of bug 1806805 ***