[CLSA-2025:1750780819] Fix CVE(s): CVE-2025-31651
Type:
security
Severity:
Critical
Release date:
2025-06-24 16:00:24 UTC
Description:
* SECURITY UPDATE: Improper Neutralization of Escape, Meta, or Control Sequences vulnerability - debian/patches/CVE-2025-31651.patch: Enforces rewrite rules to preventing bypass of security constraints in specific configurations - CVE-2025-31651
Updated packages:
  • libtomcat9-embed-java_9.0.16-3ubuntu0.18.04.2+tuxcare.els13_all.deb
    sha:80ac4ed8c328b25626918954cc4e21e20439b93e
  • libtomcat9-java_9.0.16-3ubuntu0.18.04.2+tuxcare.els13_all.deb
    sha:ff2ed9dcfe991993c21e541c309b0ba50e03f148
  • tomcat9_9.0.16-3ubuntu0.18.04.2+tuxcare.els13_all.deb
    sha:d7e04a4089b9aef8dd9383c0054cc68901f01dfd
  • tomcat9-admin_9.0.16-3ubuntu0.18.04.2+tuxcare.els13_all.deb
    sha:a3b1fd7d8e3a0066be7184b6cdd9014fa1e3b747
  • tomcat9-common_9.0.16-3ubuntu0.18.04.2+tuxcare.els13_all.deb
    sha:e6e3cdef9f11c899594ed902ecca33df190216d1
  • tomcat9-docs_9.0.16-3ubuntu0.18.04.2+tuxcare.els13_all.deb
    sha:e3023a2ecbbefbf2dfd80574c098a63181bbbfe4
  • tomcat9-examples_9.0.16-3ubuntu0.18.04.2+tuxcare.els13_all.deb
    sha:c3912f0adb8a827d422a5ecc1a515206f6edc047
  • tomcat9-user_9.0.16-3ubuntu0.18.04.2+tuxcare.els13_all.deb
    sha:937b7026c2403f4b45dbfc256be8ceec4f853129
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.