REDHAT-BUG-2457044: Low severity Apache Tomcat vulnerability
Improper Encoding or Escaping of Output vulnerability in the JsonAccessLogValve component of Apache Tomcat.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.20, from 10.1.0-M1 through 10.1.53, from 9.0.40 through 9.0.116.
Users are recommended to upgrade to version 11.0.21, 10.1.54 or 9.0.117 , which fix the issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache Tomcatto a version that resolves this vulnerability.Fixed in 11.0.21 - Upgrade
Upgrade
Apache Tomcatto a version that resolves this vulnerability.Fixed in 10.1.54 - Upgrade
Upgrade
Apache Tomcatto a version that resolves this vulnerability.Fixed in 9.0.117
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2457044?
The severity of REDHAT-BUG-2457044 is classified as low.
What is the nature of the vulnerability identified in REDHAT-BUG-2457044?
REDHAT-BUG-2457044 is an Improper Encoding or Escaping of Output vulnerability in the JsonAccessLogValve component of Apache Tomcat.
Which versions of Apache Tomcat are affected by REDHAT-BUG-2457044?
Apache Tomcat versions 11.0.0-M1 through 11.0.20, 10.1.0-M1 through 10.1.53, and 9.0.40 through 9.0.116 are affected.
How do I fix REDHAT-BUG-2457044?
To fix REDHAT-BUG-2457044, users are recommended to upgrade to Apache Tomcat version 11.0.21, 10.1.54 or later.
When was REDHAT-BUG-2457044 published?
REDHAT-BUG-2457044 was published on April 9, 2026.