Why is pki-servlet-engine marked as 'Will not fix' for newer CVEs?
Issue
- The tomcat version included in the
pki-servlet-engine
is affected by some newer vulnerabilities like CVE-2023-42795, CVE-2023-44487, and CVE-2023-45648 but it is marked asWill not fix
for these. Shouldn't these still be addressed under the product lifecycle?
Environment
- Red Hat Enterprise Linux
- Red Hat Satellite 6
- Red Hat Certificate System
- pki-servlet-engine
Subscriber exclusive content
A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.