#8751 Tomcat Vulnerability CVE-2020-1935
Closed: invalid by rcritten. Opened by talkarrohan.

HI,

We are planning to migrate our 389DS to FreeIPA. For testing we setup test FreeIPA server as below.

Hosting = AWS Instance
OS = Centos 7 (7.7.1908)
IPA Version = 4.6.8, API_VERSION: 2.237

We installed ipa server using yum, at that time by default tomcat version 7.0.76.0 gets installed.

After performing security scan we found many vulnerability for apache tomcat 7.0.76.0.

On below suggestion we tried to upgrade tomcat to fix vulnerability but its getting failed with attached error.

https://www.rapid7.com/db/vulnerabilities/apache-tomcat-cve-2020-1935/

As tomcat 7.0.76.0 comes from yum repository & now don't have update through yum we compiled (Ver. 7.0.108) from source code same as 7.0.76.0.

Can you help us how can we upgrade tomcat to fix vulnerability.

Regards,
Ron

error.jpg


This was fixed in RHEL 7.9 in November, 2020: https://bugzilla.redhat.com/show_bug.cgi?id=1806835 via https://access.redhat.com/errata/RHSA-2020:5020

We have no control over packages in CentOS.

Metadata Update from @rcritten:
- Issue close_status updated to: invalid
- Issue status updated to: Closed (was: Open)

Metadata