Apache Under the Lens: Tomcat’s Partial PUT and Camel’s Header Hijack


In March 2025, Apache disclosed CVE-2025-24813, a vulnerability impacting Apache Tomcat. This is a widely used platform that allows Apache web servers to run Java-based web applications.

The flaw allows remote code execution, affecting Apache Tomcat versions 9.0.0.M1 to 9.0.98, 10.1.0-M1 to 10.1.34 and 11.0.0-M1 to 11.0.2. The same month, Apache revealed two additional vulnerabilities in Apache Camel, a message routing middleware framework. These vulnerabilities are CVE-2025-27636 and CVE-2025-29891, two flaws that allow remote code execution, affecting Apache Camel versions 4.10.0 to 4.10.1, 4.8.0 to 4.8.4 and 3.10.0 to 3.22.3. These vulnerabilities are significant because millions of developers rely on the platform provided by the Apache Foundation.

Read more…
Source: Palo Alto Unit 42


Sign up for the Cyber Security Review Newsletter
The latest news and insights delivered right to your inbox.


Related:

  • Infosys subsidiary hit by cyber security attack

    November 3, 2023

    Infosys announced on Friday, November 3, that its US unit, Infosys McCamish Systems, was impacted by a cyber security event, resulting in the non-availability of certain applications and systems. The IT services major said it is working with a cyber security company to resolve the issue and that it had launched an investigation to identify the ...

  • Payola ransomware operator demands remote access to PC

    November 3, 2023

    The Sonicwall threat research team have recently been tracking a new ransomware family called Payola. This family of ransomware appeared in late August 2023. It is written in .NET and is easy to analyze as it contains no obfuscation. Early variants would append “.Payola” to the names of encrypted files but the current variants use ...

  • UK: Huge data breach at Southend-on-Sea City Council

    November 2, 2023

    Details of over 2,000 staff and councillors have been made public in a council data breach. Southend-on-Sea City Council could face six-figure fines for the mistake. The information disclosed included names, addresses and National Insurance numbers. The council leader has apologised and said that all those affected would be contacted and offered advice and support. ...

  • Mortgage and loan giant Mr. Cooper blames cyberattack for ongoing outage

    November 2, 2023

    Mortgage and loan giant Mr. Cooper says a “cybersecurity incident” earlier this week was the cause of an ongoing outage, adding that the company is “working to resolve the issue.” The Texas-based company said in a statement on its website that on October 31, Mr. Cooper “became the target of a cyber security incident and took ...

  • Boeing confirms ‘cyber incident’ after ransomware gang claims data theft

    November 2, 2023

    Aerospace giant Boeing has confirmed that it is dealing with a “cyber incident,” days after the company was listed on the leak site of the LockBit ransomware gang. In a statement given to TechCrunch, Boeing spokesperson Jim Prolux confirmed that attackers had targeted “elements of our parts and safety business.” The spokesperson added: “This issue does ...

  • Atlassian update: “Take immediate action” to patch your Confluence Data Center and Server instances

    November 2, 2023

    Atlassian has released an advisory about a critical severity authentication vulnerability in the Confluence Server and Data Center. All versions of Confluence Data Center and Server are affected by this unexploited vulnerability. Atlassian Cloud sites are not impacted by this vulnerability, so if your Confluence site is accessed via an atlassian.net domain, it is not ...