3.7

CVE-2021-43980

Apache Tomcat: Information disclosure

The simplified implementation of blocking reads and writes introduced in Tomcat 10 and back-ported to Tomcat 9.0.47 onwards exposed a long standing (but extremely hard to trigger) concurrency bug in Apache Tomcat 10.1.0 to 10.1.0-M12, 10.0.0-M1 to 10.0.18, 9.0.0-M1 to 9.0.60 and 8.5.0 to 8.5.77 that could cause client connections to share an Http11Processor instance resulting in responses, or part responses, to be received by the wrong client.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Apache ≫ Tomcat Version >= 8.5.0 <= 8.5.77
Apache ≫ Tomcat Version >= 9.0.0 <= 9.0.60
Apache ≫ Tomcat Version >= 10.0.0 <= 10.0.18
Apache ≫ Tomcat Version 10.1.0 Update milestone1
Apache ≫ Tomcat Version 10.1.0 Update milestone10
Apache ≫ Tomcat Version 10.1.0 Update milestone11
Apache ≫ Tomcat Version 10.1.0 Update milestone12
Apache ≫ Tomcat Version 10.1.0 Update milestone2
Apache ≫ Tomcat Version 10.1.0 Update milestone3
Apache ≫ Tomcat Version 10.1.0 Update milestone4
Apache ≫ Tomcat Version 10.1.0 Update milestone5
Apache ≫ Tomcat Version 10.1.0 Update milestone6
Apache ≫ Tomcat Version 10.1.0 Update milestone7
Apache ≫ Tomcat Version 10.1.0 Update milestone8
Apache ≫ Tomcat Version 10.1.0 Update milestone9
Debian ≫ Debian Linux Version 10.0
Debian ≫ Debian Linux Version 11.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.98% 0.785
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 3.7 2.2 1.4
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
CISA-ADP 3.7 2.2 1.4
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
CWE-362 Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

The product contains a concurrent code sequence that requires temporary, exclusive access to a shared resource, but a timing window exists in which the shared resource can be modified by another code sequence operating concurrently.

https://lists.debian.org/debian-lts-announce/2022/10/msg00029.html
Third Party Advisory
Mailing List
https://www.debian.org/security/2022/dsa-5265
Third Party Advisory
http://www.openwall.com/lists/oss-security/2022/09/28/1
Third Party Advisory
Mailing List
https://lists.apache.org/thread/3jjqbsp6j88b198x5rmg99b1qr8ht3g3
Vendor Advisory
Mailing List