Unnamed repository
- Resolves: RHEL-219561 Security constraint bypass via improper URL encoding in rewrite valve (CVE-2026-59083) - Resolves: RHEL-219581 Insufficient documentation for EncryptInterceptor may lead to insecure configurations (CVE-2026-59084) - Resolves: RHEL-238206 tomcat: Information disclosure due to HTTP Authentication Header exposure during WebSocket authentication (CVE-2026-42498) - Resolves: RHEL-238213 tomcat: Improper Handling of Case Sensitivity in LockOutRealm (CVE-2026-43513) - Resolves: RHEL-238260 tomcat: Improper Authorization allows security bypass (CVE-2026-43515) - Resolves: RHEL-238294 tomcat: Authentication bypass via digest authentication (CVE-2026-43512) - Resolves: RHEL-239018 tomcat: Apache Tomcat: Authentication bypass via missing critical step in JNDIRealm GSSAPI configuration (CVE-2026-55957) |
||
|---|---|---|
| .fmf | ||
| plans | ||
| .gitignore | ||
| ci.fmf | ||
| gating.yaml | ||
| java-9-start-up-parameters.conf | ||
| remove-bnd-annotation.patch | ||
| rhbz-1857043.patch | ||
| sources | ||
| tomcat-9.0-bootstrap-MANIFEST.MF.patch | ||
| tomcat-9.0-catalina-policy.patch | ||
| tomcat-9.0-digest.script | ||
| tomcat-9.0-tomcat-users-webapp.patch | ||
| tomcat-9.0-tool-wrapper.script | ||
| tomcat-9.0.conf | ||
| tomcat-9.0.logrotate | ||
| tomcat-9.0.service | ||
| tomcat-9.0.sysconfig | ||
| tomcat-9.0.wrapper | ||
| tomcat-build.patch | ||
| tomcat-functions | ||
| tomcat-named.service | ||
| tomcat-preamble | ||
| tomcat-server | ||
| tomcat.spec | ||