While investigating bug 64830 it was discovered that Apache Tomcat 10.0.0-M1 to 10.0.0-M9, 9.0.0-M1 to 9.0.39 and 8.5.0 to 8.5.59 could re-use an HTTP request header value from the previous stream received on an HTTP/2 connection for the request associated with the subsequent stream. While this would most likely lead to an error and the closure of the HTTP/2 connection, it is possible that information could leak between requests.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | — | Upgrade tomcat-webappsUpgrade tomcat-jsp-2.3-apiUpgrade tomcat-el-3.0-apiUpgrade tomcat-admin-webappsUpgrade tomcat-servlet-3.1-apiUpgrade tomcat-libUpgrade tomcatUpgrade tomcat-jsvcUpgrade tomcat-javadocUpgrade tomcat-docs-webapp | Sep 28, 2023 | Dec 3, 2020 |
| Amazon_linux | — | Upgrade tomcat8 | Dec 19, 2020 | Dec 3, 2020 |
| Apache Tomcat | — | Upgrade Apache Tomcat to 9.0.40Upgrade Apache Tomcat to 8.5.60Upgrade Apache Tomcat to 10.0.0Upgrade Apache Tomcat to the latest available version | Dec 4, 2020 | Dec 3, 2020 |
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | Dec 3, 2020 |
| Debian | — | Upgrade tomcat9 | Dec 18, 2020 | Dec 3, 2020 |
| Gentoo Linux | — | Upgrade www-servers/tomcat. | Dec 29, 2020 | Dec 3, 2020 |
| Huawei Euleros 2_0_sp8 | — | Upgrade tomcatUpgrade tomcat-admin-webappsUpgrade tomcat-servlet-4.0-apiUpgrade tomcat-jsp-2.3-apiUpgrade tomcat-el-3.0-apiUpgrade tomcat-lib | Feb 2, 2021 | Dec 3, 2020 |
| Oracle Missing Cpu Apr 2021 | — | Apply the April 2021 Critical Patch Update (CPU) for Oracle Database | Apr 21, 2021 | Dec 3, 2020 |
| Oracle Solaris | — | Upgrade web/java-servlet/tomcat-8/tomcat-admin to version 8.5.60-11.4.29.0.1.82.2 on Solaris 11.4Upgrade web/java-servlet/tomcat-8 to version 8.5.60-11.4.29.0.1.82.2 on Solaris 11.4Upgrade web/java-servlet/tomcat-8/tomcat-examples to version 8.5.60-11.4.29.0.1.82.2 on Solaris 11.4 | Jan 19, 2021 | Dec 3, 2020 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Dec 3, 2020 |
| Suse | — | Upgrade tomcat-docs-webappUpgrade tomcat-javadocUpgrade tomcat-webappsUpgrade tomcat-admin-webappsUpgrade tomcat-servlet-4_0-apiUpgrade tomcat-embedUpgrade tomcat-jsp-2_3-apiUpgrade tomcat-el-3_0-apiUpgrade tomcatUpgrade tomcat-libUpgrade tomcat-jsvc | Jan 6, 2021 | Dec 3, 2020 |
| Ubuntu | — | Upgrade tomcat9Upgrade tomcat9-commonUpgrade libtomcat9-javaUpgrade libtomcat9-embed-java | Apr 1, 2022 | Dec 3, 2020 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Dec 3, 2020 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub