Bug 2406590 (CVE-2025-55754)
| Summary: | CVE-2025-55754 org.apache.tomcat/tomcat-juli: tomcat: Apache Tomcat: console manipulation | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | OSIDB Bzimport <bzimport> |
| Component: | vulnerability | Assignee: | Product Security DevOps Team <prodsec-dev> |
| Status: | NEW --- | QA Contact: | |
| Severity: | medium | Docs Contact: | |
| Priority: | medium | ||
| Version: | unspecified | CC: | aakkiang, aschwart, asoldano, aszczucz, bbaranow, bmaxwell, boliveir, brian.stansberry, bstansbe, cfu, csutherl, darran.lofthouse, dhanak, dlofthou, dosoudil, drichtar, drosa, dsirrine, dsoumis, edewata, fmariani, gkimetto, gmalinko, ibek, istudens, ivassile, iweiss, janstey, jclere, jmagne, jrokos, kverlaen, mfargett, michael.h.hall-1, mnovotny, mosmerov, mposolda, msvehla, nwallace, pberan, pbizzarr, pdelbell, pesilva, pjindal, plodge, pmackay, prisingh, rmartinc, rmaucher, rstancel, rstepani, sausingh, sdawley, skhandel, smaestri, snegrini, ssilvert, sthorger, szappis, taherrin, tcunning, teagle, thjenkin, tom.jenkinson, vdosoudi, vmuzikar, yfang |
| Target Milestone: | --- | Keywords: | Security |
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | --- | |
| Doc Text: |
An improper input neutralization flaw has been discovered in Apache Tomcat.
Tomcat did not escape ANSI escape sequences in log messages. If Tomcat was running in a console on a Windows operating system, and the console supported ANSI escape sequences, it was possible for an attacker to use a specially crafted URL to inject ANSI escape sequences to manipulate the console and the clipboard and attempt to trick an administrator into running an attacker controlled command. While no attack vector was found, it may have been possible to mount this attack on other operating systems.
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | Type: | --- | |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
| Bug Depends On: | 2406639, 2406640, 2406637, 2406638 | ||
| Bug Blocks: | |||
|
Description
OSIDB Bzimport
2025-10-27 18:01:53 UTC
This issue has been addressed in the following products: Red Hat JBoss Web Server 6.2.0 Via RHSA-2026:2741 https://access.redhat.com/errata/RHSA-2026:2741 This issue has been addressed in the following products: Red Hat JBoss Web Server 6.2 on RHEL 10 Red Hat JBoss Web Server 6.2 on RHEL 8 Red Hat JBoss Web Server 6.2 on RHEL 9 Via RHSA-2026:2740 https://access.redhat.com/errata/RHSA-2026:2740 This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2026:18536 https://access.redhat.com/errata/RHSA-2026:18536 This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2026:18537 https://access.redhat.com/errata/RHSA-2026:18537 This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2026:18916 https://access.redhat.com/errata/RHSA-2026:18916 |