Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2025-52434

Опубликовано: 10 июл. 2025
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS3: 7.5

Описание

Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability in Apache Tomcat when using the APR/Native connector. This was particularly noticeable with client initiated closes of HTTP/2 connections. This issue affects Apache Tomcat: from 9.0.0.M1 through 9.0.106. Users are recommended to upgrade to version 9.0.107, which fixes the issue.

РелизСтатусПримечание
devel

not-affected

esm-apps/bionic

needs-triage

esm-apps/focal

needs-triage

esm-apps/jammy

needs-triage

esm-apps/noble

not-affected

jammy

needs-triage

noble

not-affected

9.0.70-2ubuntu0.1
plucky

not-affected

upstream

released

9.0.70-2

Показывать по

EPSS

Процентиль: 40%
0.00179
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 5.3
redhat
24 дня назад

Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability in Apache Tomcat when using the APR/Native connector. This was particularly noticeable with client initiated closes of HTTP/2 connections. This issue affects Apache Tomcat: from 9.0.0.M1 through 9.0.106. Users are recommended to upgrade to version 9.0.107, which fixes the issue.

CVSS3: 7.5
nvd
24 дня назад

Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability in Apache Tomcat when using the APR/Native connector. This was particularly noticeable with client initiated closes of HTTP/2 connections. This issue affects Apache Tomcat: from 9.0.0.M1 through 9.0.106. Users are recommended to upgrade to version 9.0.107, which fixes the issue.

CVSS3: 7.5
debian
24 дня назад

Concurrent Execution using Shared Resource with Improper Synchronizati ...

CVSS3: 7.5
github
24 дня назад

Apache Tomcat Utilities is vulnerable to resource exhaustion when using the APR/Native connector

CVSS3: 5.6
fstec
25 дней назад

Уязвимость сервера приложений Apache Tomcat, связанная с ошибками синхронизации при использовании общего ресурса («Ситуация гонки»), позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 40%
0.00179
Низкий

7.5 High

CVSS3