216.73.217.22

Apache Under the Lens: Tomcat's Partial PUT and Camel's Header Hijack

· Published 03/07/2025 11:10 · Modified 03/07/2025 17:48

Export JSON

Essential information

Published
03/07/2025 11:10
Modified
03/07/2025 17:48
Tags
2025-07-03 CVE-2025-24813 CVE-2025-27636 CVE-2025-29891 apache exploit remote code execution tomcat vulnerability
Related entities
12 vulnerabilities (cve), 23 observables, 6 techniques (mitre)

Description

In March 2025, disclosed three critical vulnerabilities: in and and in Camel. These flaws allow , affecting millions of developers. The exploits partial PUT requests and session persistence features, while the Camel vulnerabilities involve header manipulation. attempts were observed from over 70 countries, with a surge in activity immediately after disclosure. The article provides detailed analysis of the vulnerabilities, including source code examination, exploitation methods, and telemetry data. It also outlines protection measures and mitigation strategies for affected systems.

External references