[CLSA-2026:1775739369] pki-servlet-engine: Fix of 3 CVEs
Type:
security
Severity:
Important
Release date:
2026-04-09 12:56:13 UTC
Description:
- CVE-2024-52316: fix JASPIC authentication bypass on ServerAuthContext exception - CVE-2025-55754: fix ANSI escape sequence injection in log messages - CVE-2025-46701: fix CGI servlet case sensitivity bypass of security constraints
Updated packages:
  • pki-servlet-4.0-api-9.0.50-1.el9_2.2.tuxcare.els2.noarch.rpm
    sha:a25735abdc18c471d0ff0cbc33e52d2eb56a0caeb02e9ff25da2168016a95d62
  • pki-servlet-engine-9.0.50-1.el9_2.2.tuxcare.els2.noarch.rpm
    sha:dd275e83b3deba5d6870359f5598fd38b8f11fd3202240cbb2af9244dc52babc
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.