Description:
The Apache Software Foundation released security updates to address the vulnerabilities in the Apache Tomcat. A remote attacker could exploit the vulnerabilities by sending a specially crafted request to the affected systems.
Affected Systems:
- Apache Tomcat 11.0.0-M1 to 11.0.0-M26
- Apache Tomcat 10.1.0-M1 to 10.1.31
- Apache Tomcat 9.0.0-M1 to 9.0.96
Impact:
Successful exploitation of the vulnerabilities could lead to privilege escalation, security restriction bypass or spoofing on an affected system.
Recommendation:
The Apache Software Foundation has released new versions of the software to address the issue and they can be downloaded at the following URLs:
https://tomcat.apache.org/download-11.cgi#11.0.1
https://tomcat.apache.org/download-10.cgi#10.1.33
https://tomcat.apache.org/download-90.cgi#9.0.97
More Information:
- https://tomcat.apache.org/security-9.html#Fixed_in_Apache_Tomcat_9.0.96
- https://tomcat.apache.org/security-9.html#Fixed_in_Apache_Tomcat_9.0.97
- https://tomcat.apache.org/security-10.html#Fixed_in_Apache_Tomcat_10.1.31
- https://tomcat.apache.org/security-10.html#Fixed_in_Apache_Tomcat_10.1.33
- https://tomcat.apache.org/security-11.html#Fixed_in_Apache_Tomcat_11.0.0
- https://tomcat.apache.org/security-11.html#Fixed_in_Apache_Tomcat_11.0.1
- https://www.hkcert.org/security-bulletin/apache-tomcat-multiple-vulnerabilities_20241119
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-52316 (to CVE-2024-52318)