Bug 2388226 (CVE-2025-55668)
| Summary: | CVE-2025-55668 org.apache.tomcat/tomcat-catalina: tomcat: Apache Tomcat: session fixation via rewrite valve | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | OSIDB Bzimport <bzimport> |
| Component: | vulnerability | Assignee: | Product Security DevOps Team <prodsec-dev> |
| Status: | NEW --- | QA Contact: | |
| Severity: | medium | Docs Contact: | |
| Priority: | medium | ||
| Version: | unspecified | CC: | aakkiang, aschwart, asoldano, aszczucz, bbaranow, ben.argyle, bmaxwell, boliveir, brian.stansberry, bstansbe, cfu, csutherl, darran.lofthouse, dhanak, dkreling, dlofthou, dosoudil, drichtar, drosa, dsirrine, dsoumis, eaguilar, edewata, gastarit, gkimetto, gmalinko, ibek, istudens, ivassile, iweiss, janstey, jclere, jmagne, jrokos, kverlaen, mfargett, mnovotny, mosmerov, mposolda, msochure, msvehla, nwallace, pberan, pdelbell, pesilva, pjindal, plodge, pmackay, prisingh, rmartinc, rmaucher, rstancel, rstepani, sausingh, sdawley, skhandel, smaestri, snegrini, ssilvert, sthorger, szappis, taherrin, teagle, thjenkin, tom.jenkinson, vchlup, vdosoudi, vmuzikar |
| Target Milestone: | --- | Keywords: | Security |
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | --- | |
| Doc Text: |
A session fixation vulnerability has been identified in Apache Tomcat, affecting its rewrite functionality. If the rewrite valve is enabled for a web application, an attacker can craft a specific URL. If a victim clicks on this malicious URL, their subsequent interaction with the resource will occur within the context of the attacker's session. This could allow an attacker to hijack the victim's session and perform actions on their behalf.
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | Type: | --- | |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
| Bug Depends On: | 2388416, 2388417, 2394345, 2394346 | ||
| Bug Blocks: | |||
|
Description
OSIDB Bzimport
2025-08-13 14:01:09 UTC
This issue has been addressed in the following products: Red Hat JBoss Web Server 6.2.0 Via RHSA-2026:2741 https://access.redhat.com/errata/RHSA-2026:2741 This issue has been addressed in the following products: Red Hat JBoss Web Server 6.2 on RHEL 10 Red Hat JBoss Web Server 6.2 on RHEL 8 Red Hat JBoss Web Server 6.2 on RHEL 9 Via RHSA-2026:2740 https://access.redhat.com/errata/RHSA-2026:2740 This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2026:18536 https://access.redhat.com/errata/RHSA-2026:18536 This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2026:18537 https://access.redhat.com/errata/RHSA-2026:18537 This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2026:18916 https://access.redhat.com/errata/RHSA-2026:18916 Can we please have a fix for the Red Hat Enterprise Linux 8? Rebasing to 9.0.110 as for RHEL 9 would be fantastic. If at the same time the dependency on OpenJDK 1.8.0 could also be removed, that would be great! |