The vendor explicitly identifies these products as affected by this CVE.
- tomcat as a component of Red Hat Enterprise Linux 10
- tomcat-admin-webapps as a component of Red Hat Enterprise Linux 10
- tomcat-docs-webapp as a component of Red Hat Enterprise Linux 10
- tomcat-el-5.0-api as a component of Red Hat Enterprise Linux 10
- tomcat-jsp-3.1-api as a component of Red Hat Enterprise Linux 10
- tomcat-lib as a component of Red Hat Enterprise Linux 10
- tomcat-servlet-6.0-api as a component of Red Hat Enterprise Linux 10
- tomcat-webapps as a component of Red Hat Enterprise Linux 10
- tomcat.src as a component of Red Hat Enterprise Linux 10
- tomcat9 as a component of Red Hat Enterprise Linux 10
- tomcat9-admin-webapps as a component of Red Hat Enterprise Linux 10
- tomcat9-docs-webapp as a component of Red Hat Enterprise Linux 10
- Summary
- Apache Tomcat did not validate HTTP/2 request headers, triggering unexpected application behavior, as applications may presume that header values exposed through the Servlet API would be valid.
- Remediation
- Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258
