PatchSiren cyber security CVE debrief
CVE-2025-24813 Apache CVE debrief
CVE-2025-24813 is an Apache Tomcat path equivalence vulnerability that CISA added to its Known Exploited Vulnerabilities catalog on 2025-04-01, indicating it should be treated as a high-priority defensive item. The available official guidance is to apply vendor mitigations, follow applicable BOD 22-01 guidance for cloud services, or discontinue use if mitigations are unavailable.
- Vendor
- Apache
- Product
- Tomcat
- CVSS
- Unknown
- CISA KEV
- Listed
- Original CVE published
- 2025-04-01
- Original CVE updated
- 2025-04-01
- Advisory published
- 2025-04-01
- Advisory updated
- 2025-04-01
Who should care
Administrators and security teams running Apache Tomcat, especially in internet-facing or cloud-hosted environments, should prioritize this issue because it is on CISA’s KEV catalog.
Technical summary
The official records identify the issue as a path equivalence vulnerability in Apache Tomcat. The supplied source set does not provide deeper technical mechanics, so the safest assumption is that Tomcat path handling or normalization may allow unintended equivalence between paths. CISA’s KEV listing means the vulnerability is considered known exploited and warrants urgent remediation planning.
Defensive priority
High. CISA listed CVE-2025-24813 in KEV on 2025-04-01 with a remediation deadline of 2025-04-22, so affected environments should be reviewed and addressed immediately.
Recommended defensive actions
- Check whether Apache Tomcat is present in your environment, including embedded or bundled deployments.
- Apply vendor-provided mitigations or updates as directed by Apache.
- If mitigations are unavailable, discontinue use of the affected product or deployment path.
- For cloud services, follow applicable CISA BOD 22-01 guidance.
- Validate exposure in internet-facing and externally accessible systems first.
- Track remediation against the CISA KEV due date of 2025-04-22.
Evidence notes
Source evidence is limited to official records and CISA KEV metadata. The KEV entry names Apache Tomcat, describes the issue as a path equivalence vulnerability, and lists required action as applying vendor mitigations or discontinuing use if mitigations are unavailable. No CVSS score was supplied in the provided corpus.
Sources and references
Verified primary and authoritative sources
-
CVE-2025-24813 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2025-24813
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2025-24813 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2025-24813
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
-
CISA Known Exploited Vulnerabilities catalog
Publisher, destination, and source semantics verified
URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog
Cybersecurity and Infrastructure Security Agency - Official CISA catalog of vulnerabilities known to be exploited in the wild.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json
cisa_kev
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.