ALASTOMCAT9-2023-004

Related Vulnerabilities: CVE-2022-22965  

A flaw was found in Spring Framework, specifically within two modules called Spring MVC and Spring WebFlux, (transitively affected from Spring Beans), using parameter data binding. This flaw allows an attacker to pass specially-constructed malicious requests to certain parameters and possibly gain access to normally-restricted functionality within the Java Virtual Machine. (CVE-2022-22965)

ALASTOMCAT9-2023-004


Amazon Linux 2 Security Advisory: ALASTOMCAT9-2023-004
Advisory Release Date: 2023-08-21 20:58 Pacific
Advisory Updated Date: 2023-09-25 21:57 Pacific
Severity: Important

Issue Overview:

A flaw was found in Spring Framework, specifically within two modules called Spring MVC and Spring WebFlux, (transitively affected from Spring Beans), using parameter data binding. This flaw allows an attacker to pass specially-constructed malicious requests to certain parameters and possibly gain access to normally-restricted functionality within the Java Virtual Machine. (CVE-2022-22965)


Affected Packages:

tomcat


Issue Correction:
Run yum update tomcat to update your system.

New Packages:
noarch:
    tomcat-9.0.65-1.amzn2.0.1.noarch
    tomcat-admin-webapps-9.0.65-1.amzn2.0.1.noarch
    tomcat-docs-webapp-9.0.65-1.amzn2.0.1.noarch
    tomcat-jsvc-9.0.65-1.amzn2.0.1.noarch
    tomcat-jsp-2.3-api-9.0.65-1.amzn2.0.1.noarch
    tomcat-lib-9.0.65-1.amzn2.0.1.noarch
    tomcat-servlet-4.0-api-9.0.65-1.amzn2.0.1.noarch
    tomcat-el-3.0-api-9.0.65-1.amzn2.0.1.noarch
    tomcat-webapps-9.0.65-1.amzn2.0.1.noarch

src:
    tomcat-9.0.65-1.amzn2.0.1.src