Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-55276

Опубликовано: 29 июн. 2026
Источник: redhat
CVSS3: 2.3

Описание

Always-Incorrect Control Flow Implementation vulnerability in Apache Tomcat meant that special roles and empty authorisation constraints were not included when the effective web.xml was logged. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.22, from 10.1.0-M1 through 10.1.55, from 9.0.0.M1 through 9.0.118, from 8.5.0 through 8.5.100. Other versions that have reached end of support may also be affected. Users are recommended to upgrade to version 11.0.23, 10.1.56 or 9.0.119 which fixes the issue.

A flaw was found in Apache Tomcat. Due to an always-incorrect control flow implementation, special roles and empty authorization constraints were not accurately included when the effective web.xml configuration was logged. This could lead to a security oversight where administrators might misinterpret the actual authorization constraints, potentially impacting the security posture of the application.

Отчет

A flaw was found in Apache Tomcat. When the effective web.xml logging feature is enabled for debugging, special roles and empty authorization constraints may be omitted from the logged output. This is a logging-only issue with no runtime security impact — it only affects the accuracy of debug log output for administrators reviewing the effective web.xml configuration.

Меры по смягчению последствий

This is a logging-only issue with no runtime security impact. No mitigation is required. Administrators should not rely solely on the effective web.xml debug log output to verify security constraint configuration.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10tomcatFix deferred
Red Hat Enterprise Linux 10tomcat9Fix deferred
Red Hat Enterprise Linux 6tomcat6Fix deferred
Red Hat Enterprise Linux 7tomcatFix deferred
Red Hat Enterprise Linux 8pki-deps:10.6/pki-servlet-engineFix deferred
Red Hat Enterprise Linux 8tomcatFix deferred
Red Hat Enterprise Linux 9pki-servlet-engineFix deferred
Red Hat Enterprise Linux 9tomcatFix deferred
Red Hat JBoss Web Server 5jws5-tomcatFix deferred
Red Hat JBoss Web Server 6tomcat-catalinaAffected

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-778
https://bugzilla.redhat.com/show_bug.cgi?id=2494675tomcat: Apache Tomcat: Misleading security logs due to incorrect control flow

2.3 Low

CVSS3

Связанные уязвимости

CVSS3: 9.1
ubuntu
3 месяца назад

Always-Incorrect Control Flow Implementation vulnerability in Apache Tomcat meant that special roles and empty authorisation constraints were not included when the effective web.xml was logged. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.22, from 10.1.0-M1 through 10.1.55, from 9.0.0.M1 through 9.0.118, from 8.5.0 through 8.5.100. Other versions that have reached end of support may also be affected. Users are recommended to upgrade to version 11.0.23, 10.1.56 or 9.0.119 which fixes the issue.

CVSS3: 9.1
nvd
3 месяца назад

Always-Incorrect Control Flow Implementation vulnerability in Apache Tomcat meant that special roles and empty authorisation constraints were not included when the effective web.xml was logged. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.22, from 10.1.0-M1 through 10.1.55, from 9.0.0.M1 through 9.0.118, from 8.5.0 through 8.5.100. Other versions that have reached end of support may also be affected. Users are recommended to upgrade to version 11.0.23, 10.1.56 or 9.0.119 which fixes the issue.

CVSS3: 9.1
debian
3 месяца назад

Always-Incorrect Control Flow Implementation vulnerability in Apache T ...

CVSS3: 9.1
redos
28 дней назад

Уязвимость tomcat11

CVSS3: 9.1
redos
28 дней назад

Уязвимость tomcat10

2.3 Low

CVSS3