THE Apache Tomcat team has released a security update addressing 11 vulnerabilities, including three classified as Important, relating to authentication bypass, security constraint bypass, and denial of service issues. The vulnerabilities affect versions up to 11.0.24 and require updates to versions 11.0.25, 10.1.58, or 9.0.121.
While none of the vulnerabilities have been confirmed as actively exploited in the wild, it is crucial for users to apply the updates to mitigate potential risks associated with authentication and access control failures.