Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-h6c8-rg87-f3pc

Опубликовано: 17 мая 2022
Источник: github
Github: Прошло ревью

Описание

Apache Tomcat HTTP BIO Connector Error Discloses Information From Different Requests to Remote Users

The HTTP BIO connector in Apache Tomcat 7.0.x before 7.0.12 does not properly handle HTTP pipelining, which allows remote attackers to read responses intended for other clients in opportunistic circumstances by examining the application data in HTTP packets, related to "a mix-up of responses for requests from different users."

Пакеты

Наименование

org.apache.tomcat:tomcat

maven
Затронутые версииВерсия исправления

>= 7.0.0, < 7.0.12

7.0.12

EPSS

Процентиль: 93%
0.11701
Средний

Дефекты

CWE-20

Связанные уязвимости

ubuntu
около 14 лет назад

The HTTP BIO connector in Apache Tomcat 7.0.x before 7.0.12 does not properly handle HTTP pipelining, which allows remote attackers to read responses intended for other clients in opportunistic circumstances by examining the application data in HTTP packets, related to "a mix-up of responses for requests from different users."

redhat
около 14 лет назад

The HTTP BIO connector in Apache Tomcat 7.0.x before 7.0.12 does not properly handle HTTP pipelining, which allows remote attackers to read responses intended for other clients in opportunistic circumstances by examining the application data in HTTP packets, related to "a mix-up of responses for requests from different users."

nvd
около 14 лет назад

The HTTP BIO connector in Apache Tomcat 7.0.x before 7.0.12 does not properly handle HTTP pipelining, which allows remote attackers to read responses intended for other clients in opportunistic circumstances by examining the application data in HTTP packets, related to "a mix-up of responses for requests from different users."

debian
около 14 лет назад

The HTTP BIO connector in Apache Tomcat 7.0.x before 7.0.12 does not p ...

EPSS

Процентиль: 93%
0.11701
Средний

Дефекты

CWE-20