CVE-2025-31651

Public on 2025-04-28
Modified on 2025-05-01
Description
Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache Tomcat. For a subset of unlikely rewrite rule configurations, it was possible for a specially crafted request to bypass some rewrite rules. If those rewrite rules effectively enforced security constraints, those constraints could be bypassed. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.5, from 10.1.0-M1 through 10.1.39, from 9.0.0.M1 through 9.0.102.
Severity
Medium severity
Medium
CVSS v3 Base Score
5.3
See breakdown

Affected Packages

Platform Package Release Date Advisory Status
Amazon Linux 2 - Core tomcat Not Affected
Amazon Linux 2 - Tomcat9 Extra tomcat 2025-05-21 ALAS2TOMCAT9-2025-018 Fixed
Amazon Linux 2023 tomcat10 2025-05-07 ALAS2023-2025-965 Fixed
Amazon Linux 1 tomcat7 Not Affected
Amazon Linux 1 tomcat8 Not Affected
Amazon Linux 1 tomcat80 Not Affected
Amazon Linux 2023 tomcat9 2025-05-07 ALAS2023-2025-964 Fixed

CVSS Scores

Score Type Score Vector
Amazon Linux CVSSv3 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
NVD CVSSv3 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H