Release date:
2026-08-15 03:11:48 UTC
Description:
- CVE-2025-49125: require the request path to end at the mount point or continue
past it with a /, instead of testing the mount point as a bare string prefix,
so a PreResources or PostResources set mounted below the web application root
can no longer be reached via an unexpected path that is not covered by the
same security constraints; also strip a trailing / from webAppMount in all
cases, as upstream does, so a resource set mounted on a path ending in / keeps
resolving its nested paths under the stricter check
- CVE-2026-55276: include the * and ** special roles and empty authorization
constraints when generating the effective web.xml, so the logged descriptor no
longer understates the security constraints that are actually in force
Updated packages:
-
tomcat-9.0.62-12.el9_2.1.tuxcare.els10.noarch.rpm
sha:b90724bd68438a68151fc7b690fc7dc322e7939afe078dfc15b5e7270c3b1198
-
tomcat-admin-webapps-9.0.62-12.el9_2.1.tuxcare.els10.noarch.rpm
sha:8e0744948e37d8f6ab826469239fc4c45c5f547e96a4f35d1d3fa2f9290b3d6b
-
tomcat-docs-webapp-9.0.62-12.el9_2.1.tuxcare.els10.noarch.rpm
sha:3b341cd8e04ea171765f5b98b60716a42156b614098fdb3904a93ff7b6a3c45b
-
tomcat-el-3.0-api-9.0.62-12.el9_2.1.tuxcare.els10.noarch.rpm
sha:0e2b3a6106b1e2f558c56dec8beae01cd67f51bb7a611f313e58b0a24a06a7e3
-
tomcat-jsp-2.3-api-9.0.62-12.el9_2.1.tuxcare.els10.noarch.rpm
sha:0ffacf8c5bffb28a382ce044ad721c3078c198657e93a1e8859d7eb43222cd47
-
tomcat-lib-9.0.62-12.el9_2.1.tuxcare.els10.noarch.rpm
sha:495b48567395a1c6b45436a69a19e90b94088e59376562f9ce6d09db4a74bcba
-
tomcat-servlet-4.0-api-9.0.62-12.el9_2.1.tuxcare.els10.noarch.rpm
sha:53dff4571f6fea92bc91f973e074809ee17d9af181ff54cd15f4f682a65e8e38
-
tomcat-webapps-9.0.62-12.el9_2.1.tuxcare.els10.noarch.rpm
sha:0b9d3b58f0df08edd1f67c3a8b3af9fd96079fbce57811e975deccf12b628456
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.