CVE-2021-25329: Incomplete fix for CVE-2020-9484
Last updated 2 August 2024
Other sources
The fix for CVE-2020-9484 was incomplete. When using a highly unlikely configuration edge case, the Tomcat instance was still vulnerable to CVE-2020-9484. Note that both the previously published prerequisites for CVE-2020-9484 and the previously published non-upgrade mitigations for CVE-2020-9484 also apply to this issue.
Upstream commits: Tomcat 10.0: https://github.com/apache/tomcat/commit/6d66e99ef85da93e4d2c2a536ca51aa3418bfaf4 Tomcat 9.0: https://github.com/apache/tomcat/commit/4785433a226a20df6acbea49296e1ce7e23de453 Tomcat 8.5: https://github.com/apache/tomcat/commit/93f0cc403a9210d469afc2bd9cf03ab3251c6f35 Tomcat 7.0: https://github.com/apache/tomcat/commit/74b105657ffbd1d1de80455f03446c3bbf30d1f5
Reference: http://mail-archives.apache.org/modmbox/tomcat-announce/202103.mbox/%3C811bba77-e74e-9f9b-62ca-5253a09ba84f%40apache.org%3E
— Red Hat
The fix for CVE-2020-9484 was incomplete. When using Apache Tomcat 10.0.0-M1 to 10.0.0, 9.0.0.M1 to 9.0.41, 8.5.0 to 8.5.61 or 7.0.0. to 7.0.107 with a configuration edge case that was highly unlikely to be used, the Tomcat instance was still vulnerable to CVE-2020-9494. Note that both the previously published prerequisites for CVE-2020-9484 and the previously published mitigations for CVE-2020-9484 also apply to this issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/jws5-ecjto a version that resolves this vulnerability.Fixed in 0:4.12.0-3.redhat_2.2.el7 - Upgrade
Upgrade
redhat/jws5-tomcatto a version that resolves this vulnerability.Fixed in 0:9.0.43-11.redhat_00011.1.el7 - Upgrade
Upgrade
redhat/jws5-tomcat-nativeto a version that resolves this vulnerability.Fixed in 0:1.2.26-3.redhat_3.el7 - Upgrade
Upgrade
redhat/jws5-tomcat-vaultto a version that resolves this vulnerability.Fixed in 0:1.1.8-2.Final_redhat_00003.1.el7 - Upgrade
Upgrade
redhat/jws5-ecjto a version that resolves this vulnerability.Fixed in 0:4.12.0-3.redhat_2.2.el8 - Upgrade
Upgrade
redhat/jws5-tomcatto a version that resolves this vulnerability.Fixed in 0:9.0.43-11.redhat_00011.1.el8 - Upgrade
Upgrade
redhat/jws5-tomcat-nativeto a version that resolves this vulnerability.Fixed in 0:1.2.26-3.redhat_3.el8 - Upgrade
Upgrade
redhat/jws5-tomcat-vaultto a version that resolves this vulnerability.Fixed in 0:1.1.8-2.Final_redhat_00003.1.el8 - Upgrade
Upgrade
debian/tomcat9to a version that resolves this vulnerability.Fixed in 9.0.43-2~deb11u10Fixed in 9.0.43-2~deb11u12Fixed in 9.0.70-2Fixed in 9.0.95-1 - Upgrade
Upgrade
redhat/tomcatto a version that resolves this vulnerability.Fixed in 10.0.2 - Upgrade
Upgrade
redhat/tomcatto a version that resolves this vulnerability.Fixed in 9.0.43 - Upgrade
Upgrade
redhat/tomcatto a version that resolves this vulnerability.Fixed in 8.5.63 - Upgrade
Upgrade
redhat/tomcatto a version that resolves this vulnerability.Fixed in 7.0.108
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is CVE-2021-25329?
CVE-2021-25329 is a vulnerability in Apache Tomcat that allows remote attackers to execute arbitrary code or cause a denial of service.
How severe is CVE-2021-25329?
CVE-2021-25329 has a high severity rating with a CVSS score of 7.0.
Which versions of Apache Tomcat are affected by CVE-2021-25329?
CVE-2021-25329 affects Apache Tomcat versions 10.0.0-M1 to 10.0.0, 9.0.0.M1 to 9.0.41, 8.5.0 to 8.5.61, and 7.0.0 to 7.0.107.
How can I fix CVE-2021-25329?
To fix CVE-2021-25329, you should upgrade Apache Tomcat to version 10.0.2, 9.0.43, 8.5.63, or 7.0.108, depending on the affected version.
Where can I find more information about CVE-2021-25329?
You can find more information about CVE-2021-25329 at the following references: [Reference 1](https://access.redhat.com/security/cve/CVE-2020-9484), [Reference 2](https://github.com/apache/tomcat/commit/6d66e99ef85da93e4d2c2a536ca51aa3418bfaf4), [Reference 3](https://github.com/apache/tomcat/commit/4785433a226a20df6acbea49296e1ce7e23de453).