PT-2023-36244 · Apache · Apache Tomcat

Published

2023-08-08

·

Updated

2023-08-08

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions tomcat (affected versions not specified)
Description The issue is related to security hardening, specifically addressing Spring Framework vulnerabilities. This involves removing the log4j dependency, which is not used by the tomcat package, and deprecating the getResources() function to always return null.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

SUSE-SU-2023:3232-1

Affected Products

Apache Tomcat