While investigating bug 64830 it was discovered that Apache Tomcat 10.0.0-M1 to 10.0.0-M9, 9.0.0-M1 to 9.0.39 and 8.5.0 to 8.5.59 could re-use an HTTP request header value from the previous stream received on an HTTP/2 connection for the request associated with the subsequent stream. While this would most likely lead to an error and the closure of the HTTP/2 connection, it is possible that information could leak between requests.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | — | Upgrade tomcat-servlet-3.1-apiUpgrade tomcat-libUpgrade tomcat-docs-webappUpgrade tomcatUpgrade tomcat-javadocUpgrade tomcat-jsvcUpgrade tomcat-el-3.0-apiUpgrade tomcat-admin-webappsUpgrade tomcat-jsp-2.3-apiUpgrade tomcat-webapps | Sep 28, 2023 | Dec 3, 2020 |
| Amazon_linux | — | Upgrade tomcat8 | Dec 19, 2020 | Dec 3, 2020 |
| Apache Tomcat | — | Upgrade Apache Tomcat to the latest available versionUpgrade Apache Tomcat to 8.5.60Upgrade Apache Tomcat to 10.0.0Upgrade Apache Tomcat to 9.0.40 | Dec 4, 2020 | Dec 3, 2020 |
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | Dec 3, 2020 |
| Debian | — | Upgrade tomcat9 | Dec 18, 2020 | Dec 3, 2020 |
| Gentoo Linux | — | Upgrade www-servers/tomcat. | Dec 29, 2020 | Dec 3, 2020 |
| Huawei Euleros 2_0_sp8 | — | Upgrade tomcat-admin-webappsUpgrade tomcatUpgrade tomcat-jsp-2.3-apiUpgrade tomcat-servlet-4.0-apiUpgrade tomcat-el-3.0-apiUpgrade tomcat-lib | Feb 2, 2021 | Dec 3, 2020 |
| Oracle Missing Cpu Apr 2021 | — | Apply the April 2021 Critical Patch Update (CPU) for Oracle Database | Apr 21, 2021 | Dec 3, 2020 |
| Oracle Solaris | — | Upgrade web/java-servlet/tomcat-8/tomcat-admin to version 8.5.60-11.4.29.0.1.82.2 on Solaris 11.4Upgrade web/java-servlet/tomcat-8 to version 8.5.60-11.4.29.0.1.82.2 on Solaris 11.4Upgrade web/java-servlet/tomcat-8/tomcat-examples to version 8.5.60-11.4.29.0.1.82.2 on Solaris 11.4 | Jan 19, 2021 | Dec 3, 2020 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Dec 3, 2020 |
| Suse | — | Upgrade tomcat-jsvcUpgrade tomcatUpgrade tomcat-embedUpgrade tomcat-libUpgrade tomcat-el-3_0-apiUpgrade tomcat-jsp-2_3-apiUpgrade tomcat-servlet-4_0-apiUpgrade tomcat-webappsUpgrade tomcat-docs-webappUpgrade tomcat-admin-webappsUpgrade tomcat-javadoc | Jan 6, 2021 | Dec 3, 2020 |
| Ubuntu | — | Upgrade libtomcat9-javaUpgrade libtomcat9-embed-javaUpgrade tomcat9-commonUpgrade tomcat9 | Apr 1, 2022 | Dec 3, 2020 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Dec 3, 2020 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub