File _patchinfo of Package patchinfo.7942
<patchinfo incident="7942"> <issue id="1082480" tracker="bnc">VUL-0: CVE-2018-1304: tomcat: Incorrect handling of empty string URL in security constraints can lead to unitended exposure of resources</issue> <issue id="1082481" tracker="bnc">VUL-0: CVE-2018-1305: tomcat: Late application of security constraints can lead to resource exposure for unauthorised users</issue> <issue id="1078677" tracker="bnc">VUL-1: CVE-2017-15706: tomcat: Incorrect documentation of CGI Servlet search algorithm may lead to misconfiguration</issue> <issue id="2017-15706" tracker="cve" /> <issue id="2018-1305" tracker="cve" /> <issue id="2018-1304" tracker="cve" /> <category>security</category> <rating>moderate</rating> <packager>malbu</packager> <description>This update for tomcat fixes the following issues: Security issues fixed: - CVE-2018-1305: Fixed late application of security constraints that can lead to resource exposure for unauthorised users (bsc#1082481). - CVE-2018-1304: Fixed incorrect handling of empty string URL in security constraints that can lead to unitended exposure of resources (bsc#1082480). - CVE-2017-15706: Fixed incorrect documentation of CGI Servlet search algorithm that may lead to misconfiguration (bsc#1078677). This update was imported from the SUSE:SLE-12-SP2:Update update project.</description> <summary>Security update for tomcat</summary> </patchinfo>