• 公告ID (KylinSec-SA-2022-1488)

摘要:

The documentation of Apache Tomcat 10.1.0-M1 to 10.1.0-M14, 10.0.0-M1 to 10.0.20, 9.0.13 to 9.0.62 and 8.5.38 to 8.5.78 for the EncryptInterceptor incorrectly stated it enabled Tomcat clustering to run over an untrusted network. This was not correct. While the EncryptInterceptor does provide confidentiality and integrity protection, it does not protect against all risks associated with running over any untrusted network, particularly DoS risks.

安全等级: Low

公告ID: KylinSec-SA-2022-1488

发布日期: 2022年5月28日

关联CVE: CVE-2022-29885  

  • 详细介绍

1. 漏洞描述

   

The documentation of Apache Tomcat 10.1.0-M1 to 10.1.0-M14, 10.0.0-M1 to 10.0.20, 9.0.13 to 9.0.62 and 8.5.38 to 8.5.78 for the EncryptInterceptor incorrectly stated it enabled Tomcat clustering to run over an untrusted network. This was not correct. While the EncryptInterceptor does provide confidentiality and integrity protection, it does not protect against all risks associated with running over any untrusted network, particularly DoS risks.

2. 影响范围

cve名称 产品 组件 是否受影响
CVE-2022-29885 KY3.4-4A tomcat Unaffected
CVE-2022-29885 KY3.4-5A tomcat Unaffected
CVE-2022-29885 KY3.5.1 tomcat Unaffected

3. 影响组件

    无

4. 修复版本

    无

5. 修复方法

   无

6. 下载链接

    无
上一篇:KylinSec-SA-2022-1487 下一篇:KylinSec-SA-2022-1489