Impact
Off-by-one error in the [N] flag of the RewriteValve causes rewrite processing to restart at the second rule instead of the first. This behavior can allow a request to bypass configured access‑control checks, potentially exposing protected resources. The flaw is an off‑by‑one boundary condition (CWE‑193).
Affected Systems
The flaw affects Apache Tomcat from 11.0.0‑M1 through 11.0.24, from 10.1.0‑M1 through 10.1.57, and from 9.0.0.M1 through 9.0.120. Versions 8.5.0 through 8.5.100, which were already end‑of‑life, also remain vulnerable.
Risk and Exploitability
Because the issue requires manipulating rewrite rules, the attack vector is application‑level via crafted URLs. No publicly available exploit is documented and EPSS < 1%; however, the potential to bypass access control renders the risk moderate to high for any exposed Tomcat instance, with a CVSS score of 7.5. The vulnerability is not listed in the CISA KEV catalog.
OpenCVE Enrichment