Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-jx7c-7mj5-9438

Опубликовано: 29 сент. 2022
Источник: github
Github: Прошло ревью
CVSS3: 3.7

Описание

Apache Tomcat Race Condition vulnerability

The simplified implementation of blocking reads and writes introduced in Tomcat 10 and back-ported to Tomcat 9.0.47 onwards exposed a long standing (but extremely hard to trigger) concurrency bug in Apache Tomcat 10.1.0 to 10.1.0-M12, 10.0.0-M1 to 10.0.18, 9.0.0-M1 to 9.0.60 and 8.5.0 to 8.5.77 that could cause client connections to share an Http11Processor instance resulting in responses, or part responses, to be received by the wrong client.

Пакеты

Наименование

org.apache.tomcat:tomcat

maven
Затронутые версииВерсия исправления

>= 8.5.0, < 8.5.78

8.5.78

Наименование

org.apache.tomcat:tomcat

maven
Затронутые версииВерсия исправления

>= 9.0.0-M1, < 9.0.62

9.0.62

Наименование

org.apache.tomcat:tomcat

maven
Затронутые версииВерсия исправления

>= 10.0.0-M1, < 10.0.20

10.0.20

Наименование

org.apache.tomcat:tomcat

maven
Затронутые версииВерсия исправления

>= 10.1.0-M1, < 10.1.0-M14

10.1.0-M14

EPSS

Процентиль: 38%
0.00162
Низкий

3.7 Low

CVSS3

Дефекты

CWE-362

Связанные уязвимости

CVSS3: 3.7
ubuntu
больше 2 лет назад

The simplified implementation of blocking reads and writes introduced in Tomcat 10 and back-ported to Tomcat 9.0.47 onwards exposed a long standing (but extremely hard to trigger) concurrency bug in Apache Tomcat 10.1.0 to 10.1.0-M12, 10.0.0-M1 to 10.0.18, 9.0.0-M1 to 9.0.60 and 8.5.0 to 8.5.77 that could cause client connections to share an Http11Processor instance resulting in responses, or part responses, to be received by the wrong client.

CVSS3: 3.7
redhat
больше 2 лет назад

The simplified implementation of blocking reads and writes introduced in Tomcat 10 and back-ported to Tomcat 9.0.47 onwards exposed a long standing (but extremely hard to trigger) concurrency bug in Apache Tomcat 10.1.0 to 10.1.0-M12, 10.0.0-M1 to 10.0.18, 9.0.0-M1 to 9.0.60 and 8.5.0 to 8.5.77 that could cause client connections to share an Http11Processor instance resulting in responses, or part responses, to be received by the wrong client.

CVSS3: 3.7
nvd
больше 2 лет назад

The simplified implementation of blocking reads and writes introduced in Tomcat 10 and back-ported to Tomcat 9.0.47 onwards exposed a long standing (but extremely hard to trigger) concurrency bug in Apache Tomcat 10.1.0 to 10.1.0-M12, 10.0.0-M1 to 10.0.18, 9.0.0-M1 to 9.0.60 and 8.5.0 to 8.5.77 that could cause client connections to share an Http11Processor instance resulting in responses, or part responses, to be received by the wrong client.

CVSS3: 3.7
debian
больше 2 лет назад

The simplified implementation of blocking reads and writes introduced ...

suse-cvrf
больше 2 лет назад

Security update for tomcat

EPSS

Процентиль: 38%
0.00162
Низкий

3.7 Low

CVSS3

Дефекты

CWE-362