Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-ff77-26x5-69cr

Опубликовано: 28 апр. 2025
Источник: github
Github: Прошло ревью
CVSS4: 2.7

Описание

Apache Tomcat Rewrite rule bypass

Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache Tomcat. For a subset of unlikely rewrite rule configurations, it was possible for a specially crafted request to bypass some rewrite rules. If those rewrite rules effectively enforced security constraints, those constraints could be bypassed.

This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.5, from 10.1.0-M1 through 10.1.39, from 9.0.0.M1 through 9.0.102.

Users are recommended to upgrade to version 9.0.104, 10.1.40 or 11.0.6, which fix the issue.

Пакеты

Наименование

org.apache.tomcat:tomcat-catalina

maven
Затронутые версииВерсия исправления

>= 9.0.76, <= 9.0.102

9.0.104

Наименование

org.apache.tomcat:tomcat-catalina

maven
Затронутые версииВерсия исправления

>= 10.1.10, < 10.1.40

10.1.40

Наименование

org.apache.tomcat:tomcat-catalina

maven
Затронутые версииВерсия исправления

>= 11.0.0-M2, < 11.0.6

11.0.6

Наименование

org.apache.tomcat.embed:tomcat-embed-core

maven
Затронутые версииВерсия исправления

>= 9.0.76, <= 9.0.102

9.0.104

Наименование

org.apache.tomcat.embed:tomcat-embed-core

maven
Затронутые версииВерсия исправления

>= 10.1.10, < 10.1.40

10.1.40

Наименование

org.apache.tomcat.embed:tomcat-embed-core

maven
Затронутые версииВерсия исправления

>= 11.0.0-M2, < 11.0.6

11.0.6

EPSS

Процентиль: 23%
0.00073
Низкий

2.7 Low

CVSS4

Дефекты

CWE-116
CWE-150

Связанные уязвимости

CVSS3: 9.8
ubuntu
около 2 месяцев назад

Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache Tomcat. For a subset of unlikely rewrite rule configurations, it was possible for a specially crafted request to bypass some rewrite rules. If those rewrite rules effectively enforced security constraints, those constraints could be bypassed. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.5, from 10.1.0-M1 through 10.1.39, from 9.0.0.M1 through 9.0.102. Users are recommended to upgrade to version [FIXED_VERSION], which fixes the issue.

CVSS3: 5.3
redhat
около 2 месяцев назад

Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache Tomcat. For a subset of unlikely rewrite rule configurations, it was possible for a specially crafted request to bypass some rewrite rules. If those rewrite rules effectively enforced security constraints, those constraints could be bypassed. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.5, from 10.1.0-M1 through 10.1.39, from 9.0.0.M1 through 9.0.102. Users are recommended to upgrade to version [FIXED_VERSION], which fixes the issue.

CVSS3: 9.8
nvd
около 2 месяцев назад

Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache Tomcat. For a subset of unlikely rewrite rule configurations, it was possible for a specially crafted request to bypass some rewrite rules. If those rewrite rules effectively enforced security constraints, those constraints could be bypassed. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.5, from 10.1.0-M1 through 10.1.39, from 9.0.0.M1 through 9.0.102. Users are recommended to upgrade to version [FIXED_VERSION], which fixes the issue.

CVSS3: 9.8
debian
около 2 месяцев назад

Improper Neutralization of Escape, Meta, or Control Sequences vulnerab ...

suse-cvrf
8 дней назад

Security update for tomcat

EPSS

Процентиль: 23%
0.00073
Низкий

2.7 Low

CVSS4

Дефекты

CWE-116
CWE-150