[CLSA-2025:1765903038] tomcat: Fix of CVE-2025-55752
Type:
security
Severity:
Important
Release date:
2025-12-16 16:37:22 UTC
Description:
- CVE-2025-55752: fix relative path traversal vulnerability by normalizing rewritten URLs before decoding to prevent bypassing security constraints and potential remote code execution via PUT requests
Updated packages:
  • tomcat-9.0.62-11.el9_2.3.tuxcare.els15.noarch.rpm
    sha:2b20009d0d95936779bba9df5660365baa92e4958bc995a5440f7625ccc51ddd
  • tomcat-admin-webapps-9.0.62-11.el9_2.3.tuxcare.els15.noarch.rpm
    sha:b950c84925dc9ffcf9c9058e2b23b71cac1aaa5de6e8858d4c47808ea6212601
  • tomcat-docs-webapp-9.0.62-11.el9_2.3.tuxcare.els15.noarch.rpm
    sha:475de73d656893fa654ae5e4ecc55728339d6370a22dbe6f629e3a48c2940d24
  • tomcat-el-3.0-api-9.0.62-11.el9_2.3.tuxcare.els15.noarch.rpm
    sha:50b2c266869090fc9fe02385b12b786735e497aef844d338e309adfc5e45e617
  • tomcat-jsp-2.3-api-9.0.62-11.el9_2.3.tuxcare.els15.noarch.rpm
    sha:61e65b7eb07ef3c3a1d25c2787fc4df42b2be631f0780ffccf47b929327c375e
  • tomcat-lib-9.0.62-11.el9_2.3.tuxcare.els15.noarch.rpm
    sha:1eaaaa79a19d73323a3bf945bfda1e05bb20eba5aed5b6a084eb62abad15fd8d
  • tomcat-servlet-4.0-api-9.0.62-11.el9_2.3.tuxcare.els15.noarch.rpm
    sha:4c6450d1054ce7ec6f8bf6ba1c96697c1067d481cdea92a8f672e4cb3db0d1f1
  • tomcat-webapps-9.0.62-11.el9_2.3.tuxcare.els15.noarch.rpm
    sha:1ee41064f9aadd696edf01feffdabfcaaa3aec97befd70f947e88b7eab181940
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.