CVE-2025-31651
CRITICAL9.8EPSS 0.20%Apache Tomcat: Bypass of rules in Rewrite Valve
描述
Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache Tomcat. For a subset of unlikely rewrite rule configurations, it was possible for a specially crafted request to bypass some rewrite rules. If those rewrite rules effectively enforced security constraints, those constraints could be bypassed. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.5, from 10.1.0-M1 through 10.1.39, from 9.0.0.M1 through 9.0.102. The following versions were EOL at the time the CVE was created but are known to be affected: 8.5.0 though 8.5.100. Other, older, EOL versions may also be affected. Users are recommended to upgrade to version [FIXED_VERSION], which fixes the issue.
受影響套件(6)
- Bitnami/tomcatfrom 0, < 9.0.104, >= 10.0.0, < 10.1.40, >= 11.0.0, < 11.0.6
- Debian/tomcat10from 0, < 10.1.40-1
- Debian/tomcat11from 0, < 11.0.6-1
- Debian/tomcat9from 0, < 9.0.107-0+deb11u1
- Maven/org.apache.tomcat.embed:tomcat-embed-core>= 9.0.76, < 9.0.104
- Maven/org.apache.tomcat:tomcat-catalina>= 9.0.76, < 9.0.104
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 4.0 | — | CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:U |
| osv | CVSS 3.1 | CRITICAL9.8 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
參考連結(13)
- ADVISORYhttps://nvd.nist.gov/vuln/detail/CVE-2025-31651
- ADVISORYhttps://security-tracker.debian.org/tracker/CVE-2025-31651
- PATCHhttps://github.com/apache/tomcat
- WEBhttps://github.com/apache/tomcat/commit/066bf6b6a15a4e7e0941d4acf096841165b97098
- WEBhttps://github.com/apache/tomcat/commit/175dc75fc428930034a6c93fb52f830d955d8e64
- WEBhttps://github.com/apache/tomcat/commit/ee3ab548e92345eca0cbd1f01649eb36c6f29454
- WEBhttps://github.com/apache/tomcat/commit/fbecc915a10c5a3d634c5e2c6ced4ff479ce9953
- WEBhttps://lists.apache.org/[email protected]
- WEBhttps://lists.debian.org/debian-lts-announce/2025/07/msg00009.html
- WEBhttps://tomcat.apache.org/security-10.html
- WEBhttps://tomcat.apache.org/security-11.html
- WEBhttps://tomcat.apache.org/security-9.html
- WEBhttp://www.openwall.com/lists/oss-security/2025/04/28/3