Описание
Improper Handling of URL Encoding (Hex Encoding) vulnerability in Apache Tomcat's rewrite valve allowed security constraint bypass for some configurations.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.23, from 10.1.0-M1 through 10.1.56, from 9.0.0.M1 through 9.0.119, from 8.5.0 through 8.5.100. Other versions that have reached end of support may also be affected.
Users are recommended to upgrade to version 11.0.24, 10.1.57 or 9.0.120, which fix the issue.
A flaw was found in Apache Tomcat. This vulnerability, located in the rewrite valve, is due to improper handling of URL encoding (hex encoding). A remote attacker could exploit this to bypass security constraints in certain configurations, potentially gaining unauthorized access or performing actions that should be restricted.
Отчет
This Low impact vulnerability in Apache Tomcat's rewrite valve allows a security constraint bypass through improper URL encoding. Exploitation requires specific configurations and has high attack complexity, limiting its overall risk to Red Hat products.
Меры по смягчению последствий
To mitigate this issue, review Apache Tomcat's rewrite valve configurations. If the rewrite valve is not essential for your application, consider disabling it. If it is required, ensure its configuration does not permit improper URL encoding that could lead to security constraint bypasses. A service restart may be required for changes to take effect.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 10 | tomcat | Affected | ||
| Red Hat Enterprise Linux 10 | tomcat9 | Affected | ||
| Red Hat Enterprise Linux 6 | tomcat6 | Out of support scope | ||
| Red Hat Enterprise Linux 7 | tomcat | Out of support scope | ||
| Red Hat Enterprise Linux 8 | pki-deps:10.6/pki-servlet-engine | Affected | ||
| Red Hat Enterprise Linux 8 | tomcat | Affected | ||
| Red Hat Enterprise Linux 9 | pki-servlet-engine | Affected | ||
| Red Hat Enterprise Linux 9 | tomcat | Affected | ||
| Red Hat JBoss Web Server 5 | jws5-tomcat | Affected | ||
| Red Hat Hardened Images | tomcat11-main-11.0.24-0.1.hum1 | Fixed | RHSA-2026:36872 | 08.07.2026 |
Показывать по
Дополнительная информация
Статус:
EPSS
3.7 Low
CVSS3
Связанные уязвимости
Improper Handling of URL Encoding (Hex Encoding) vulnerability in Apache Tomcat's rewrite valve allowed security constraint bypass for some configurations. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.23, from 10.1.0-M1 through 10.1.56, from 9.0.0.M1 through 9.0.119, from 8.5.0 through 8.5.100. Other versions that have reached end of support may also be affected. Users are recommended to upgrade to version 11.0.24, 10.1.57 or 9.0.120, which fix the issue.
Improper Handling of URL Encoding (Hex Encoding) vulnerability in Apache Tomcat's rewrite valve allowed security constraint bypass for some configurations. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.23, from 10.1.0-M1 through 10.1.56, from 9.0.0.M1 through 9.0.119, from 8.5.0 through 8.5.100. Other versions that have reached end of support may also be affected. Users are recommended to upgrade to version 11.0.24, 10.1.57 or 9.0.120, which fix the issue.
Improper Handling of URL Encoding (Hex Encoding) vulnerability in Apac ...
Improper Handling of URL Encoding (Hex Encoding) vulnerability in Apache Tomcat's rewrite valve allowed security constraint bypass for some configurations. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.23, from 10.1.0-M1 through 10.1.56, from 9.0.0.M1 through 9.0.119, from 8.5.0 through 8.5.100. Other versions that have reached end of support may also be affected. Users are recommended to upgrade to version 11.0.24, 10.1.57 or 9.0.120, which fix the issue.
EPSS
3.7 Low
CVSS3