Listen to this Post
The vulnerability stems from a regression introduced by the fix for bug 60013. The flawed code normalized the URL before URL decoding, creating a logic error in the request processing pipeline. For configurations using RewriteRule directives that map query parameters into the URL path, an attacker can craft a malicious request with encoded path traversal sequences (e.g., `%2e%2e%2f` for ../). Because normalization, which resolves ../, occurs on the still-encoded URL, these sequences are not correctly interpreted. Subsequent URL decoding then reveals the traversal sequence, allowing access to restricted directories like `/WEB-INF/` or /META-INF/. If the HTTP PUT method is enabled, this flaw can be leveraged to upload a malicious JSP file directly into a web-accessible directory, ultimately leading to Remote Code Execution.
Platform: Apache Tomcat
Version: 8.5.60-100, 9.0.40-108
Vulnerability: Path Traversal
Severity: High
date: 2025-10-27
Prediction: 2025-11-10
What Undercode Say:
curl -X PUT 'http://target:8080/app/..%2fWEB-INF/web.xml' -d @malicious_file.jsp
<Valve className="org.apache.catalina.valves.rewrite.RewriteValve" />
// Flawed logic: normalize -> decode String normalized = RequestUtil.normalize(encodedURI); String decoded = URLDecoder.decode(normalized, "UTF-8");
How Exploit:
Craft requests with encoded `../` sequences in parameters mapped by RewriteRule to bypass security constraints and access/WEB-INF. If PUT is enabled, upload a JSP webshell for RCE.
Protection from this CVE
Upgrade to Tomcat 11.0.11+, 10.1.45+, or 9.0.109+. Disable PUT method if unused. Review and audit all RewriteRule configurations.
Impact:
Information Disclosure. Remote Code Execution.
🎯Let’s Practice Exploiting & Learn Patching For Free:
Sources:
Reported By: github.com
Extra Source Hub:
Undercode

