File _patchinfo of Package patchinfo.39191
<patchinfo incident="39191"> <issue tracker="bnc" id="1242722">Harden permissions for tomcat package</issue> <issue tracker="bnc" id="1243815" /> <issue tracker="bnc" id="1244656" /> <issue tracker="bnc" id="1244649" /> <issue tracker="cve" id="2025-46701" /> <issue tracker="cve" id="2025-48988" /> <issue tracker="cve" id="2025-49125" /> <packager>mbussolotto</packager> <rating>important</rating> <category>security</category> <summary>Security update for tomcat</summary> <description>This update for tomcat fixes the following issues: - CVE-2025-46701: Fixed refactor CGI servlet to access resources via WebResources (bsc#1243815). - CVE-2025-48988: Fixed limits the total number of parts in a multi-part request and limits the size of the headers provided with each part (bsc#1244656). - CVE-2025-49125: Fixed expand checks for webAppMount (bsc#1244649). Other bugfixes: - Made permissions more secure (bsc#1242722) </description> </patchinfo>