- Resolves: RHEL-219561 Security constraint bypass via improper URL encoding in rewrite valve (CVE-2026-59083) - Resolves: RHEL-219581 Insufficient documentation for EncryptInterceptor may lead to insecure configurations (CVE-2026-59084) - Resolves: RHEL-238206 tomcat: Information disclosure due to HTTP Authentication Header exposure during WebSocket authentication (CVE-2026-42498) - Resolves: RHEL-238213 tomcat: Improper Handling of Case Sensitivity in LockOutRealm (CVE-2026-43513) - Resolves: RHEL-238260 tomcat: Improper Authorization allows security bypass (CVE-2026-43515) - Resolves: RHEL-238294 tomcat: Authentication bypass via digest authentication (CVE-2026-43512) - Resolves: RHEL-239018 tomcat: Apache Tomcat: Authentication bypass via missing critical step in JNDIRealm GSSAPI configuration (CVE-2026-55957)
2 lines
173 B
Plaintext
2 lines
173 B
Plaintext
SHA512 (apache-tomcat-9.0.120-src.tar.gz) = db8230bb08b1c33ea710b71fbba1de3d0c84c6416a784921333c03ef6526c1b022b0b2ad18686b734babba538500da795e46bf5bbbd789d8a7a251ffb3665a59
|