Vulnerability for Tomcat CVE-2024-50379
Hello,
we have reported a vulnerability for versions of tomcat shipped with RHEL 9.
https://access.redhat.com/security/cve/cve-2024-50379
So far we haven t seen any fix for this, and the fixes suggested (upgrade to tomcat 9.0.98) seems that are not supported/shipped in RHEL 9 repos.
What should we do to fix this vulnerability.
Shall we install from the apache page the versions or wait for an errata and if it is so, what is the estimated time to have an errata available.
Thank you very much for the feedback in this...
Responses