USN-6880-1: Tomcat vulnerability
9 July 2024
Tomcat could allow unintended access to network services.
Releases
Packages
- tomcat8 - Apache Tomcat 8 - Servlet and JSP engine
- tomcat9 - Apache Tomcat 9 - Servlet and JSP engine
Details
Sam Shahsavar discovered that Apache Tomcat did not properly reject
HTTP requests with an invalid Content-Length header. A remote attacker
could possibly use this issue to perform HTTP request smuggling attacks.
Update instructions
The problem can be corrected by updating your system to the following package versions:
Ubuntu 22.04
-
libtomcat9-java
-
9.0.58-1ubuntu0.1+esm1
Available with Ubuntu Pro
-
tomcat9
-
9.0.58-1ubuntu0.1+esm1
Available with Ubuntu Pro
Ubuntu 20.04
Ubuntu 18.04
-
libtomcat8-java
-
8.5.39-1ubuntu1~18.04.3+esm1
Available with Ubuntu Pro
-
libtomcat9-java
-
9.0.16-3ubuntu0.18.04.2+esm1
Available with Ubuntu Pro
-
tomcat8
-
8.5.39-1ubuntu1~18.04.3+esm1
Available with Ubuntu Pro
-
tomcat9
-
9.0.16-3ubuntu0.18.04.2+esm1
Available with Ubuntu Pro
In general, a standard system update will make all the necessary changes.