Bug 2388226 (CVE-2025-55668)

Summary: CVE-2025-55668 org.apache.tomcat/tomcat-catalina: tomcat: Apache Tomcat: session fixation via rewrite valve
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security DevOps Team <prodsec-dev>
Status: NEW --- QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedCC: aakkiang, aschwart, asoldano, bbaranow, bmaxwell, boliveir, brian.stansberry, cdewolf, cfu, csutherl, darran.lofthouse, dhanak, dkreling, dosoudil, drosa, dsirrine, dsoumis, edewata, fjuma, gkimetto, gmalinko, ibek, istudens, ivassile, iweiss, janstey, jclere, jmagne, jrokos, kverlaen, lgao, mfargett, mharmsen, mnovotny, mosmerov, mposolda, msochure, msvehla, nwallace, pdelbell, pesilva, pjindal, plodge, pmackay, prisingh, rmaucher, rstancel, rstepani, sausingh, sdawley, skhandel, smaestri, ssilvert, sthorger, szappis, taherrin, teagle, tom.jenkinson, vchlup, vmuzikar
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
A session fixation vulnerability has been identified in Apache Tomcat, affecting its rewrite functionality. If the rewrite valve is enabled for a web application, an attacker can craft a specific URL. If a victim clicks on this malicious URL, their subsequent interaction with the resource will occur within the context of the attacker's session. This could allow an attacker to hijack the victim's session and perform actions on their behalf.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 2388416, 2388417, 2394345, 2394346    
Bug Blocks:    

Description OSIDB Bzimport 2025-08-13 14:01:09 UTC
Session Fixation vulnerability in Apache Tomcat via rewrite valve.

This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.7, from 10.1.0-M1 through 10.1.41, from 9.0.0.M1 through 9.0.105.
Older, EOL versions may also be affected.

Users are recommended to upgrade to version 11.0.8, 10.1.42 or 9.0.106, which fix the issue.