
University Project of developing a template for safely testing for the CVE 2025-24813 on a server. It is intentionally made to not leave any lasting artifacts on the server and does not disrupt its activities.
This repository contains a yaml-template, to scan whether a Service may be vulnerable to CVE-2025-24813, without disrupting the server/causing any form of damage, using the vulnerability scanner nuclei.
CVE-2025-24813 is a vulnerability in the Apache Tomcat webserver from version 9.0.0-9.0.98, 10.1.0-10.1.34 and 11.0.0-11.0.2. It requires the Server to be configured to allow Write-Access via partial PUT and have persistent sessions enabled.
A potential Attack functions by writing to a file with an unexpected name making use of path equivalence via partial PUT to modify a saved Session file to contain malicious Java-Code. Attempting to interact with the server via the modified session then executes the inserted Java-code.
This template consists of three steps used to check if the Server is vulnerable:
This test specifically does not check whether persistent sessions are enabled and session-files can be written to, as this might disrupt regular server business, and thus would move this template into Exploit territory, instead of being purely reconnaissance.