Executive brief
Apache Tomcat, a widely used web server for Java applications, is vulnerable to a security flaw that could allow unauthorized access to protected system files. In specific configurations where URL rewriting is used, an attacker could bypass security restrictions to view sensitive internal directories or, in rare cases, upload malicious files to take control of the server. This could lead to data theft or a complete system compromise.
Technical details
A regression in the fix for bug 60013 causes rewritten URLs to be normalized before they are decoded. In environments using rewrite rules that map query parameters to the URL, an attacker can craft a request URI that bypasses security constraints, specifically protecting the /WEB-INF/ and /META-INF/ directories. If the server also has PUT requests enabled (typically restricted to trusted users), this path traversal can be leveraged to upload malicious files, leading to remote code execution. The vulnerability is reachable over the network but requires specific configuration conditions to be exploitable. Patches are available in versions 11.0.11, 10.1.45, and 9.0.109.
Affected products
- Apache Tomcat 11.0.0-M1 through 11.0.10, 10.1.0-M1 through 10.1.44, 9.0.0.M11 through 9.0.108, 8.5.6 through 8.5.100
Timeline
- 2025-10-27: disclosed
- 2025-10-27: advisory
- 2025-10-27: patched