MGASA-2025-0250

Advisory lineage Upstream: 3 Downstream: 0
Published: 29 Oct 2025, 04:28
Last modified:16 Apr 2026, 04:21

Vulnerability Summary

Overall Risk (default)
minimal
0/100
CVSS Score
No data
EPSS Score
No data
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

29 Oct 2025, 04:28
Published
Vulnerability first disclosed
16 Apr 2026, 04:21
Last Modified
Vulnerability information updated

Description

Updated tomcat packages fix security vulnerabilities Directory traversal via rewrite with possible RCE if PUT is enabled. (CVE-2025-55752) Console manipulation via escape sequences in log messages. (CVE-2025-55754) Delayed cleaning of multi-part upload temporary files may lead to DoS. (CVE-2025-61795)

Affected Systems

  • mageiatomcat

    < 9.0.111-1.mga9

References (5)