CLSA-2023-1691083477

    Dashboard / Vulnerabilities / CLSA-2023-1691083477

    CLSA-2023-1691083477

    Published: 3 Aug 2023Last Modified: 4 Jun 2026

    Summary: Fix CVE(s): CVE-2021-25329, CVE-2022-23181, CVE-2020-9484

    Details: * SECURITY UPDATE: Remote Code Execution via session persistence - debian/patches/CVE-2020-9484.patch: Improve validation of storage location when using FileStore. - CVE-2020-9484 * SECURITY UPDATE: Fix for CVE-2020-9484 was incomplete - debian/patches/CVE-2021-25329-pre1.patch: Fix some edge cases where the docBase was not being set using a canonical path which in turn meant resource URLs were not being constructed as expected. - debian/patches/CVE-2021-25329.patch: Use java.nio.file.Path for consistent sub-directory checking. - CVE-2021-25329 * SECURITY UPDATE: Local Privilege Escalation - debian/patches/CVE-2022-23181.patch: Make calculation of session storage location more robust. - CVE-2022-23181 * Update the expired test certificates: - debian/test_certs/*.pem|*.jks: Take the last test certificates from the upstream branch 8.5.x. - debian/source/include-binaries: Specifying the binary *.jks files to prevent build failures. - debian/rules: Before the testing stage, the old certificates in the source code are replaced with the new ones from debian/test_certs.

    Affected packages

    Package

    Name: libtomcat8-embed-java

    Purl: pkg:deb/tuxcare/libtomcat8-embed-java?distro=ubuntu-18.04

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -8.5.39-1ubuntu1~18.04.3+tuxcare.els4

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    CLSA-2023-1691083477 | CVE-DB