CVE-2025-31651
Essential information
- Published
- 28/04/2025 20:15
- Modified
- 28/04/2025 22:15
- Author
- —
- Creator
- —
- CISA KEV
- No
- CWE
- —
- CVSS vector
- — — —
Description
Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache Tomcat. For a subset of unlikely rewrite rule configurations, it was possible
for a specially crafted request to bypass some rewrite rules. If those
rewrite rules effectively enforced security constraints, those
constraints could be bypassed.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.5, from 10.1.0-M1 through 10.1.39, from 9.0.0.M1 through 9.0.102.
Users are recommended to upgrade to version [FIXED_VERSION], which fixes the issue.
NVD status
- Status
- Received — CVE has been recently published to the CVE List and has been received by the NVD.
- Source
- [email protected]
- NVD
- View on NVD
Affected products (CPE)
| Product | CPE |
|---|---|
| apache / tomcat | cpe:2.3:a:apache:tomcat:11.0.0-M1:11.0.5:*:*:*:*:*:* |
| apache / tomcat | cpe:2.3:a:apache:tomcat:10.1.0-M1:10.1.39:*:*:*:*:*:* |
| apache / tomcat | cpe:2.3:a:apache:tomcat:9.0.0-M1:9.0.102:*:*:*:*:*:* |