PT-2022-11965 · Apache+4 · Apache Tomcat+4

·

CVE-2021-43980

·

Published

2022-04-01

·

Updated

2026-03-26

CVSS v3.1

3.7

Low

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Apache Tomcat versions 8.5.0 through 8.5.77 Apache Tomcat versions 9.0.0-M1 through 9.0.60 Apache Tomcat versions 10.0.0-M1 through 10.0.18 Apache Tomcat versions 10.1.0 through 10.1.0-M12
Description The simplified implementation of blocking reads and writes introduced in Tomcat 10 and back-ported to Tomcat 9.0.47 onwards exposed a long standing concurrency bug that could cause client connections to share an Http11Processor instance resulting in responses, or part responses, to be received by the wrong client.
Recommendations For Apache Tomcat versions 8.5.0 through 8.5.77, update to a version outside of this range to resolve the issue. For Apache Tomcat versions 9.0.0-M1 through 9.0.60, update to a version outside of this range to resolve the issue. For Apache Tomcat versions 10.0.0-M1 through 10.0.18, update to a version outside of this range to resolve the issue. For Apache Tomcat versions 10.1.0 through 10.1.0-M12, update to a version outside of this range to resolve the issue. As a temporary workaround, consider restricting access to the Http11Processor instance to minimize the risk of exploitation.

Exploit

Fix

DoS

Race Condition

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2023-8058
ALT-PU-2025-2379
ALT-PU-2025-9146
BDU:2022-06689
BIT-TOMCAT-2021-43980
CVE-2021-43980
DLA-3160-1
DSA-5265-1
GHSA-JX7C-7MJ5-9438
MGASA-2023-0138
OESA-2024-2402
OESA-2024-2403
OESA-2024-2404
OESA-2024-2405
OESA-2024-2460
OPENSUSE-SU-2024:12534-1
OPENSUSE-SU-2024:13441-1
RHSA-2022:7272
ROSA-SA-2023-2258
SUSE-SU-2022:4009-1
SUSE-SU-2022:4221-1
SUSE-SU-2022:4257-1
SUSE-SU-2022_4009-1
SUSE-SU-2022_4221-1
SUSE-SU-2022_4257-1
SUSE-SU-2026:1058-1

Affected Products

Alt Linux
Apache Tomcat
Astra Linux
Red Os
Suse