REDHAT-BUG-2362782: Low severity Apache Tomcat vulnerability
Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache Tomcat. For a subset of unlikely rewrite rule configurations, it was possible for a specially crafted request to bypass some rewrite rules. If those rewrite rules effectively enforced security constraints, those constraints could be bypassed.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.5, from 10.1.0-M1 through 10.1.39, from 9.0.0.M1 through 9.0.102.
Users are recommended to upgrade to version [FIXEDVERSION], which fixes the issue.
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2362782?
The severity of REDHAT-BUG-2362782 is high due to the potential security risks in Apache Tomcat.
How do I fix REDHAT-BUG-2362782?
To fix REDHAT-BUG-2362782, upgrade Apache Tomcat to version 11.0.5, 10.1.39, or 9.0.102 or later.
Which versions of Apache Tomcat are affected by REDHAT-BUG-2362782?
Apache Tomcat versions prior to 11.0.5, 10.1.39, and 9.0.102 are affected by REDHAT-BUG-2362782.
What type of vulnerability is REDHAT-BUG-2362782?
REDHAT-BUG-2362782 is classified as an Improper Neutralization of Escape, Meta, or Control Sequences vulnerability.
What are the potential impacts of REDHAT-BUG-2362782?
The potential impacts of REDHAT-BUG-2362782 include the ability for attackers to bypass important security rewrite rules.