The simplified implementation of blocking reads and writes introduced in Tomcat 10 and back-ported to Tomcat 9.0.47 onwards exposed a long standing (but extremely hard to trigger) concurrency bug in Apache Tomcat 10.1.0 to 10.1.0-M12, 10.0.0-M1 to 10.0.18, 9.0.0-M1 to 9.0.60 and 8.5.0 to 8.5.77 that could cause client connections to share an Http11Processor instance resulting in responses, or part responses, to be received by the wrong client.
CVSS Details
- CVSS 3.1 Base Score: 3.7
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | — | Upgrade tomcat-jsp-2.3-apiUpgrade tomcat-libUpgrade tomcat-servlet-3.1-apiUpgrade tomcat-admin-webappsUpgrade tomcat-docs-webappUpgrade tomcatUpgrade tomcat-el-3.0-apiUpgrade tomcat-javadocUpgrade tomcat-servlet-4.0-apiUpgrade tomcat-webappsUpgrade tomcat-jsvc | Sep 28, 2023 | Sep 28, 2022 |
| Amazon_linux | — | Upgrade tomcat8 | Apr 21, 2023 | Sep 28, 2022 |
| Apache Tomcat | — | Upgrade Apache Tomcat to 9.0.62Upgrade Apache Tomcat to the latest available versionUpgrade Apache Tomcat to 10.0.20Upgrade Apache Tomcat to 8.5.78Upgrade Apache Tomcat to 10.1.0 | Sep 29, 2022 | Sep 28, 2022 |
| Debian | — | Upgrade tomcat9 | Oct 28, 2022 | Sep 28, 2022 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Sep 28, 2022 |
| Suse | — | Upgrade tomcat-docs-webappUpgrade tomcatUpgrade tomcat-admin-webappsUpgrade tomcat-javadocUpgrade tomcat-el-3_0-apiUpgrade tomcat-webappsUpgrade tomcat-libUpgrade tomcat-servlet-4_0-apiUpgrade tomcat-jsp-2_3-api | Nov 17, 2022 | Sep 28, 2022 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub