CVE-2020-13943Medium· 4.3▾ SunlitIf an HTTP/2 client connecting to Apache Tomcat 10.0.0-M1 to 10.0.0-M7, 9.0.0.M1 to 9.0.37 or 8.5.0 to 8.5.57 exceeded the agreed maximum number of concurrent streams for a connection (in violation of the HTTP/2 protocol), it was possibl…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 23.7 · likelihood 11 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
55%
If an HTTP/2 client connecting to Apache Tomcat 10.0.0-M1 to 10.0.0-M7, 9.0.0.M1 to 9.0.37 or 8.5.0 to 8.5.57 exceeded the agreed maximum number of concurrent streams for a connection (in violation of the HTTP/2 protocol), it was possible that a subsequent request made on that connection could contain HTTP headers - including HTTP/2 pseudo headers - from a previous request rather than the intended headers. This could lead to users seeing responses for unexpected resources.
tomcat = 8.5.0tomcat = 8.5.1tomcat = 8.5.2tomcat = 8.5.3tomcat = 8.5.4tomcat = 8.5.5tomcat = 8.5.6tomcat = 8.5.7tomcat = 8.5.8tomcat = 8.5.9tomcat = 8.5.10tomcat = 8.5.11tomcat = 8.5.12tomcat = 8.5.13tomcat = 8.5.14tomcat = 8.5.15tomcat = 8.5.16tomcat = 8.5.17tomcat = 8.5.18tomcat = 8.5.19tomcat = 8.5.20tomcat = 8.5.21tomcat = 8.5.22tomcat = 8.5.23tomcat = 8.5.24tomcat = 8.5.25tomcat = 8.5.26tomcat = 8.5.27tomcat = 8.5.28tomcat = 8.5.29tomcat = 8.5.30tomcat = 8.5.31tomcat = 8.5.32tomcat = 8.5.33tomcat = 8.5.34tomcat = 8.5.35tomcat = 8.5.36tomcat = 8.5.37tomcat = 8.5.38tomcat = 8.5.39tomcat = 8.5.40tomcat = 8.5.41tomcat = 8.5.42tomcat = 8.5.43tomcat = 8.5.44tomcat = 8.5.45tomcat = 8.5.46tomcat = 8.5.47tomcat = 8.5.48tomcat = 8.5.49tomcat = 8.5.50tomcat = 8.5.51tomcat = 8.5.52tomcat = 8.5.53tomcat = 8.5.54tomcat = 8.5.55tomcat = 8.5.56tomcat = 8.5.57tomcat = 9.0.0tomcat = 9.0.1tomcat = 9.0.2tomcat = 9.0.3tomcat = 9.0.4tomcat = 9.0.5tomcat = 9.0.6tomcat = 9.0.7tomcat = 9.0.8tomcat = 9.0.9tomcat = 9.0.10tomcat = 9.0.11tomcat = 9.0.12tomcat = 9.0.13tomcat = 9.0.14tomcat = 9.0.15tomcat = 9.0.16tomcat = 9.0.17tomcat = 9.0.18tomcat = 9.0.19tomcat = 9.0.20tomcat = 9.0.21tomcat = 9.0.22tomcat = 9.0.23tomcat = 9.0.24tomcat = 9.0.25tomcat = 9.0.26tomcat = 9.0.27tomcat = 9.0.28tomcat = 9.0.29tomcat = 9.0.30tomcat = 9.0.31tomcat = 9.0.32tomcat = 9.0.33tomcat = 9.0.34tomcat = 9.0.35tomcat = 9.0.36tomcat = 9.0.37tomcat = 10.0.0debian_linux = 9.0debian_linux = 10.0instantis_enterprisetrack = 17.1Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2020-17527High· 7.5While investigating bug 64830 it was discovered that Apache Tomcat 10.0.0-M1 to 10.0.0-M9, 9.0.0-M1 to 9.0.39 and 8.5.0 to 8.5.59 could re-use an HTTP request header value from the previous stream received on an HTTP/2 connection for the…
CVE-2020-13935High· 7.5The payload length in a WebSocket frame was not correctly validated in Apache Tomcat 10.0.0-M1 to 10.0.0-M6, 9.0.0.M1 to 9.0.36, 8.5.0 to 8.5.56 and 7.0.27 to 7.0.104
CVE-2020-13934High· 7.5An h2c direct connection to Apache Tomcat 10.0.0-M1 to 10.0.0-M6, 9.0.0.M5 to 9.0.36 and 8.5.1 to 8.5.56 did not release the HTTP/1.1 processor after the upgrade to HTTP/2
CVE-2020-9484High· 7.0When using Apache Tomcat versions 10.0.0-M1 to 10.0.0-M4, 9.0.0.M1 to 9.0.34, 8.5.0 to 8.5.54 and 7.0.0 to 7.0.103 if a) an attacker is able to control the contents and name of a file on the server; and b) the server is configured to use…
CVE-2023-42794Medium· 5.9Incomplete Cleanup vulnerability in Apache Tomcat. The internal fork of Commons FileUpload packaged with Apache Tomcat 9.0.70 through 9.0.80 and 8.5.85 through 8.5.93 included an unreleased, in progress refactoring that exposed a poten…
CVE-2022-34305Medium· 6.1In Apache Tomcat 10.1.0-M1 to 10.1.0-M16, 10.0.0-M1 to 10.0.22, 9.0.30 to 9.0.64 and 8.5.50 to 8.5.81 the Form authentication example in the examples web application displayed user provided data without filtering, exposing a XSS vulnerab…