Bug 2388226 (CVE-2025-55668)
| Summary: | CVE-2025-55668 org.apache.tomcat/tomcat-catalina: tomcat: Apache Tomcat: session fixation via rewrite valve | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | OSIDB Bzimport <bzimport> |
| Component: | vulnerability | Assignee: | Product Security DevOps Team <prodsec-dev> |
| Status: | NEW --- | QA Contact: | |
| Severity: | medium | Docs Contact: | |
| Priority: | medium | ||
| Version: | unspecified | CC: | aakkiang, aschwart, asoldano, aszczucz, bbaranow, bmaxwell, boliveir, brian.stansberry, bstansbe, cfu, csutherl, darran.lofthouse, dhanak, dkreling, dlofthou, dosoudil, drichtar, drosa, dsirrine, dsoumis, eaguilar, edewata, gastarit, gkimetto, gmalinko, ibek, istudens, ivassile, iweiss, janstey, jclere, jmagne, jrokos, kverlaen, mfargett, mharmsen, mnovotny, mosmerov, mposolda, msochure, msvehla, nwallace, pberan, pdelbell, pesilva, pjindal, plodge, pmackay, prisingh, rmartinc, rmaucher, rstancel, rstepani, sausingh, sdawley, skhandel, smaestri, snegrini, ssilvert, sthorger, szappis, taherrin, teagle, thjenkin, tom.jenkinson, vchlup, vdosoudi, vmuzikar |
| Target Milestone: | --- | Keywords: | Security |
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | --- | |
| Doc Text: |
A session fixation vulnerability has been identified in Apache Tomcat, affecting its rewrite functionality. If the rewrite valve is enabled for a web application, an attacker can craft a specific URL. If a victim clicks on this malicious URL, their subsequent interaction with the resource will occur within the context of the attacker's session. This could allow an attacker to hijack the victim's session and perform actions on their behalf.
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | Type: | --- | |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
| Bug Depends On: | 2388416, 2388417, 2394345, 2394346 | ||
| Bug Blocks: | |||
|
Description
OSIDB Bzimport
2025-08-13 14:01:09 UTC
This issue has been addressed in the following products: Red Hat JBoss Web Server 6.2.0 Via RHSA-2026:2741 https://access.redhat.com/errata/RHSA-2026:2741 This issue has been addressed in the following products: Red Hat JBoss Web Server 6.2 on RHEL 10 Red Hat JBoss Web Server 6.2 on RHEL 8 Red Hat JBoss Web Server 6.2 on RHEL 9 Via RHSA-2026:2740 https://access.redhat.com/errata/RHSA-2026:2740 |