Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache Tomcat. For a subset of unlikely rewrite rule configurations, it was possible
for a specially crafted request to bypass some rewrite rules. If those
rewrite rules effectively enforced security constraints, those
constraints could be bypassed.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.5, from 10.1.0-M1 through 10.1.39, from 9.0.0.M1 through 9.0.102.
Users are recommended to upgrade to version [FIXED_VERSION], which fixes the issue.
Metrics
Affected Vendors & Products
References
History
Thu, 01 May 2025 02:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
References |
| |
Metrics |
threat_severity
|
cvssV3_1
|
Mon, 28 Apr 2025 22:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
References |
|
Mon, 28 Apr 2025 19:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache Tomcat. For a subset of unlikely rewrite rule configurations, it was possible for a specially crafted request to bypass some rewrite rules. If those rewrite rules effectively enforced security constraints, those constraints could be bypassed. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.5, from 10.1.0-M1 through 10.1.39, from 9.0.0.M1 through 9.0.102. Users are recommended to upgrade to version [FIXED_VERSION], which fixes the issue. | |
Title | Apache Tomcat: Bypass of rules in Rewrite Valve | |
Weaknesses | CWE-150 | |
References |
|

Status: PUBLISHED
Assigner: apache
Published: 2025-04-28T19:17:21.721Z
Updated: 2025-04-28T22:02:47.596Z
Reserved: 2025-03-31T12:25:25.164Z
Link: CVE-2025-31651

No data.

Status : Awaiting Analysis
Published: 2025-04-28T20:15:20.783
Modified: 2025-04-29T13:52:10.697
Link: CVE-2025-31651
