PT-2022-11965 · Apache+4 · Apache Tomcat+4
CVSS v3.1
3.7
Low
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Apache Tomcat versions 8.5.0 through 8.5.77
Apache Tomcat versions 9.0.0-M1 through 9.0.60
Apache Tomcat versions 10.0.0-M1 through 10.0.18
Apache Tomcat versions 10.1.0 through 10.1.0-M12
Description
The simplified implementation of blocking reads and writes introduced in Tomcat 10 and back-ported to Tomcat 9.0.47 onwards exposed a long standing concurrency bug that could cause client connections to share an
Http11Processor instance resulting in responses, or part responses, to be received by the wrong client.Recommendations
For Apache Tomcat versions 8.5.0 through 8.5.77, update to a version outside of this range to resolve the issue.
For Apache Tomcat versions 9.0.0-M1 through 9.0.60, update to a version outside of this range to resolve the issue.
For Apache Tomcat versions 10.0.0-M1 through 10.0.18, update to a version outside of this range to resolve the issue.
For Apache Tomcat versions 10.1.0 through 10.1.0-M12, update to a version outside of this range to resolve the issue.
As a temporary workaround, consider restricting access to the
Http11Processor instance to minimize the risk of exploitation.Exploit
Fix
DoS
Race Condition
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Apache Tomcat
Astra Linux
Red Os
Suse