Apache Tomcat Open Redirect

Febna V M
Published on
10 Jan 2022


Because it fails to properly sanitise user-supplied input, Apache Tomcat versions previous to 9.0.12, 8.5.34, and 7.0.91 are vulnerable to an open-redirection vulnerability.


  • Upgrade to Apache Tomcat 9.0.12 or later.

  • Upgrade to Apache Tomcat 8.5.34 or later.

  • Upgrade to Apache Tomcat 7.0.91 or later.

  • Use mapperDirectoryRedirectEnabled=”true” and mapperContextRootRedirectEnabled=”true” on the Context to ensure that redirects are issued by the Mapper rather than the default Servlet.

Automated human-like penetration testing for your web apps & APIs
Teams using Beagle Security are set up in minutes, embrace release-based CI/CD security testing and save up to 65% with timely remediation of vulnerabilities. Sign up for a free account to see what it can do for you.

Written by
Febna V M
Febna V M
Cyber Security Engineer
Find website security issues in a flash
Improve your website's security posture with proactive vulnerability detection.
Free website security assessment