What is the Vulnerability?On March 10, 2025, Apache issued a security advisory regarding a critical vulnerability (CVE-2025-24813) affecting the Apache Tomcat web server. This flaw could allow attackers to view or inject arbitrary content into security-sensitive files and potentially achieve remote code execution.Exploit code for this vulnerability is publicly available, and no authentication is required to launch an attack, making prompt mitigation essential. According to Apache, successful exploitation requires specific conditions, many of which are enabled by default, allowing attackers to manipulate and view sensitive files or execute remote code.What is the recommended Mitigation?Impacted users should implement the recommended mitigations provided by Apache and follow the instructions outlined in the vendor’s advisory:https://lists.apache.org/thread/j5fkjv2k477os90nczf2v9l61fb0kkgq- Upgrade to Apache Tomcat 11.0.3 or later- Upgrade to Apache Tomcat 10.1.35 or later- Upgrade to Apache Tomcat 9.0.99 or laterWhat FortiGuard Coverage is available?FortiGuard Labs has available IPS protection to detect and block any attack attempts targeting the CVE-2025-24813 affecting the Apache Tomcat web server. https://www.fortiguard.com/encyclopedia/ips/57559FortiGuard Endpoint Vulnerability Service provides a systematic and automated method of patching applications on an endpoint, eliminating manual processes while reducing the attack surface. https://www.fortiguard.com/encyclopedia/endpoint-vuln/84317The FortiGuard Incident Response team can be engaged to help with any suspected compromise.
More Stories
containernetworking-plugins-1.5.1-2.fc40
FEDORA-2025-f87fe38331 Packages in this update: containernetworking-plugins-1.5.1-2.fc40 Update description: Resolve FTBFS and rhbz#2351926 Read More
matrix-synapse-1.111.1-4.fc40
FEDORA-2025-cef83410f7 Packages in this update: matrix-synapse-1.111.1-4.fc40 Update description: Backport fixes from v1.127.1 Read More
matrix-synapse-1.118.0-4.fc41
FEDORA-2025-cddcfd6518 Packages in this update: matrix-synapse-1.118.0-4.fc41 Update description: Backport fixes from v1.127.1 Read More
matrix-synapse-1.127.1-1.fc42
FEDORA-2025-63751ef564 Packages in this update: matrix-synapse-1.127.1-1.fc42 Update description: Update to v1.127.1 (CVE-2025-30355) Read More
cri-tools1.29-1.29.0-11.fc41
FEDORA-2025-37c6639afe Packages in this update: cri-tools1.29-1.29.0-11.fc41 Update description: Resolve FTBFS Resolves: rhbz#2352149 Adopt trivy for license detection to be consistent...
cri-tools1.29-1.29.0-11.fc42
FEDORA-2025-adae8279e3 Packages in this update: cri-tools1.29-1.29.0-11.fc42 Update description: Resolve FTBFS Resolves: rhbz#2352149 Adopt trivy for license detection to be consistent...