🛡️ SUSE-SU-2024:4106-1 — tomcat (CVE-2024-52316)

⚪ Unknown ✅ No Known Exploit OSV
N/A
CVSS Score
0 Low4 Medium7 High9 Critical10

Description

Security update for tomcat

This update for tomcat fixes the following issues:

  • Update to Tomcat 9.0.97
  • Fixed CVEs:

+ CVE-2024-52316: If the Jakarta Authentication fails with an exception,

set a 500 status (bsc#1233434)

  • Catalina

+ Add: Add support for the new Servlet API method

HttpServletResponse.sendEarlyHints(). (markt)

+ Add: 55470: Add debug logging that reports the class path when a

ClassNotFoundException occurs in the digester or the web application

class loader. Based on a patch by Ralf Hauser. (markt)

+ Update: 69374: Properly separate between table header and body in

DefaultServlet's listing. (michaelo)

+ Update: 69373: Make DefaultServlet's HTML listing file last modified

rendering better (flexible). (michaelo)

+ Update: Improve HTML output of DefaultServlet. (michaelo)

+ Code: Refactor RateLimitFilter to use FilterBase as the base class. The

primary advantage for doing this is less code to process init-param

values. (markt)

+ Update: 69370: DefaultServlet's HTML listing uses incorrect labels.

(michaelo)

+ Fix: Avoid NPE in CrawlerSessionManagerValve for partially mapped

requests. (remm)

+ Fix: Add missing WebDAV Lock-Token header in the response when locking

a folder. (remm)

+ Fix: Invalid WebDAV lock requests should be rejected with 400. (remm)

+ Fix: Fix regression in WebDAV when attempting to unlock a collection.

(remm)

+ Fix: Verify that destination is not locked for a WebDAV copy operation.

(remm)

+ Fix: Send 415 response to WebDAV MKCOL operations that include a

request body since this is optional and unsupported. (remm)

+ Fix: Enforce DAV: namespace on WebDAV XML elements. (remm)

+ Fix: Do not allow a new WebDAV lock on a child resource if a parent

collection is locked (RFC 4918 section 6.1). (remm)

+ Fix: WebDAV Delete should remove any existing lock on successfully

deleted resources. (remm)

+ Update: Remove WebDAV lock null support in accordance with RFC 4918

section 7.3 and annex D. Instead, a lock on a non-existing resource

will create an empty file locked with a regular lock. (remm)

+ Update: Rewrite implementation of WebDAV shared locks to comply with

RFC 4918. (remm)

+ Update: Implement WebDAV If header using code from the Apache Jackrabbit

project. (remm)

+ Add: Add PropertyStore interface in the WebDAV Servlet, to allow

implementation of dead properties storage. The store used can be

configured using the 'propertyStore' init parameter of the WebDAV

servlet. A simple non-persistent implementation is used if no custom

store is configured. (remm)

+ Update: Implement WebDAV PROPPATCH method using the newly added

PropertyStore. (remm)

+ Fix: Cache not found results when searching for web application class

loader resources. This addresses performance problems caused by

components such as java.sql.DriverManager which, in some circumstances,

will search for the same class repeatedly. In a large web application

this can cause performance problems. The size of the cache can be

controlled via the new notFoundClassResourceCacheSize on the

StandardContext. (markt)

+ Fix: Stop after INITIALIZED state should be a noop since it is possible

for subcomponents to be in FAILED after init. (remm)

+ Fix: Fix incorrect web resource cache size calculations when there are

concurrent PUT and DELETE requests for the same resource. (markt)

+ Add: Add debug logging for the web resource cache so the current size

can be tracked as resources are added and removed. (markt)

+ Update: Replace legacy WebDAV opaquelocktoken: scheme for lock tokens

with urn:uuid: as recommended by RFC 4918, and remove secret init

parameter. (remm)

+ Fix: Concurrent reads and writes (e.g. GET and PUT / DELETE) for the

same path caused corruption of the FileResource where some of the

fields were set as if the file exists and some as set as if it does

not. This resulted in inconsistent metadata. (markt)

+ Fix: 69415: Ensure that the ExpiresFilter only sets cache headers on

GET and HEAD requests. Also skip requests where the application has set

Cache-Control: no-store. (markt)

+ Fix: 69419: Improve the performance of ServletRequest.getAttribute()

when there are multiple levels of nested includes. Based on a patch

provided by John Engebretson. (markt)

+ Add: All applications to send an early hints informational response by

calling HttpServletResponse.sendError() with a status code of 103.

(schultz)

+ Fix: Ensure that the Jakarta Authentication CallbackHandler only

creates one GenericPrincipal in the Subject. (markt)

+ Fix: If the Jakarta Authentication process fails with an Exception,

Affected software

SUSE-SU-2024:4106-1 is recorded against 1 package.

  • tomcat (fixed in 9.0.97-150200.71.1)

Timeline and source

Published on 28 November 2024 and last revised on 4 February 2026. No public exploit is currently recorded for this entry. Record sourced from OSV.

References

www.suse.com (Advisory)
bugzilla.suse.com (Report)
www.suse.com (Web)

Details

Severity Unknown
CVSS Score N/A
CVSS Vector N/A
CWE N/A
Public Exploit ✅ No
Source OSV
Published 2024-11-28
Updated 2026-08-20
Modified 2026-02-04
Fix URL N/A

Affected Packages

Software From version Fixed in
tomcat 9.0.97-150200.71.1

Similar Threats

Free Vulnerability Check

Is your site affected by SUSE-SU-2024:4106-1?

BotEraser helps you identify potentially vulnerable plugins and themes by checking your installation against SUSE-SU-2024:4106-1 and other known CVE records.

Scan My Site Free →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.

Browse related advisories

All advisoriesSUSESUSE 2024