CVE-2021-43980 – org.apache.tomcat:tomcat
Package
Manager: maven
Name: org.apache.tomcat:tomcat
Vulnerable Version: >=8.5.0 <8.5.78 || >=9.0.0-m1 <9.0.62 || >=10.0.0-m1 <10.0.20 || >=10.1.0-m1 <10.1.0-m14
Severity
Level: Low
CVSS v3.1: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
CVSS v4.0: CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
EPSS: 0.00162 pctl0.37617
Details
Apache Tomcat Race Condition vulnerability The simplified implementation of blocking reads and writes introduced in Tomcat 10 and back-ported to Tomcat 9.0.47 onwards exposed a long standing (but extremely hard to trigger) concurrency bug in Apache Tomcat 10.1.0 to 10.1.0-M12, 10.0.0-M1 to 10.0.18, 9.0.0-M1 to 9.0.60 and 8.5.0 to 8.5.77 that could cause client connections to share an Http11Processor instance resulting in responses, or part responses, to be received by the wrong client.
Metadata
Created: 2022-09-29T00:00:25Z
Modified: 2024-03-11T16:38:56Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/09/GHSA-jx7c-7mj5-9438/GHSA-jx7c-7mj5-9438.json
CWE IDs: ["CWE-362"]
Alternative ID: GHSA-jx7c-7mj5-9438
Finding: F124
Auto approve: 1