CLSA-2022-1655757814

    Dashboard / Vulnerabilities / CLSA-2022-1655757814

    CLSA-2022-1655757814

    Published: 20 Jun 2022Last Modified: 4 Jun 2026

    Summary: Fix CVE(s): CVE-2020-1938, CVE-2020-9484, CVE-2021-25329

    Details: * Fix build process: - debian/keystores/*.pem|*.jks: update expiring certs and keystores - debian/patches/0028-update-expiring-test-certs.patch: update expiring test certs - debian/patches/0029-fix-path-to-valid-keystore.patch: fix path to valid keystore - debian/patches/0030-use-tls12-in-tests.patch: use TLSv1.2 protocol instead of TLSv1 for several tests * SECURITY UPDATE: AJP Request Injection and potential Remote Code Execution - debian/patches/CVE-2020-1938-1.patch: rename requiredSecret to secret and add secretRequired - debian/patches/CVE-2020-1938-2.patch: refactor secret check - debian/patches/CVE-2020-1938-3.patch: add new AJP attribute allowedArbitraryRequestAttributes - debian/patches/CVE-2020-1938-4.patch: change the default bind address for AJP to the loopback address - CVE-2020-1938 * SECURITY UPDATE: Remote Code Execution via session persistence - debian/patches/CVE-2020-9484.patch: improve validation of storage location when using FileStore - CVE-2020-9484 * SECURITY UPDATE: Fix for CVE-2020-9484 was incomplete - debian/patches/CVE-2021-25329.patch: use consistent approach for sub-directory checking - CVE-2021-25329

    Affected packages

    Package

    Name: libservlet3.0-java

    Purl: pkg:deb/tuxcare/libservlet3.0-java?distro=ubuntu-16.04

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -7.0.68-1ubuntu0.4+tuxcare.els1

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    CLSA-2022-1655757814 | CVE-DB