Логотип exploitDog
bind:CVE-2022-25762
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2022-25762

Количество 7

Количество 7

ubuntu логотип

CVE-2022-25762

около 3 лет назад

If a web application sends a WebSocket message concurrently with the WebSocket connection closing when running on Apache Tomcat 8.5.0 to 8.5.75 or Apache Tomcat 9.0.0.M1 to 9.0.20, it is possible that the application will continue to use the socket after it has been closed. The error handling triggered in this case could cause the a pooled object to be placed in the pool twice. This could result in subsequent connections using the same object concurrently which could result in data being returned to the wrong use and/or other errors.

CVSS3: 8.6
EPSS: Низкий
redhat логотип

CVE-2022-25762

около 3 лет назад

If a web application sends a WebSocket message concurrently with the WebSocket connection closing when running on Apache Tomcat 8.5.0 to 8.5.75 or Apache Tomcat 9.0.0.M1 to 9.0.20, it is possible that the application will continue to use the socket after it has been closed. The error handling triggered in this case could cause the a pooled object to be placed in the pool twice. This could result in subsequent connections using the same object concurrently which could result in data being returned to the wrong use and/or other errors.

CVSS3: 8.6
EPSS: Низкий
nvd логотип

CVE-2022-25762

около 3 лет назад

If a web application sends a WebSocket message concurrently with the WebSocket connection closing when running on Apache Tomcat 8.5.0 to 8.5.75 or Apache Tomcat 9.0.0.M1 to 9.0.20, it is possible that the application will continue to use the socket after it has been closed. The error handling triggered in this case could cause the a pooled object to be placed in the pool twice. This could result in subsequent connections using the same object concurrently which could result in data being returned to the wrong use and/or other errors.

CVSS3: 8.6
EPSS: Низкий
debian логотип

CVE-2022-25762

около 3 лет назад

If a web application sends a WebSocket message concurrently with the W ...

CVSS3: 8.6
EPSS: Низкий
github логотип

GHSA-h3ch-5pp2-vh6w

около 3 лет назад

Improper socket reuse in Apache Tomcat

CVSS3: 8.6
EPSS: Низкий
fstec логотип

BDU:2022-03062

больше 3 лет назад

Уязвимость сервера приложений Apache Tomcat, связанная с ошибками при одновременном закрытии соединения WebSocket и отправки сообщения WebSocket, позволяющая нарушителю раскрыть защищаемую информацию или оказать другое воздействие

CVSS3: 8.6
EPSS: Низкий
rocky логотип

RLSA-2020:4847

больше 4 лет назад

Moderate: pki-core:10.6 and pki-deps:10.6 security, bug fix, and enhancement update

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2022-25762

If a web application sends a WebSocket message concurrently with the WebSocket connection closing when running on Apache Tomcat 8.5.0 to 8.5.75 or Apache Tomcat 9.0.0.M1 to 9.0.20, it is possible that the application will continue to use the socket after it has been closed. The error handling triggered in this case could cause the a pooled object to be placed in the pool twice. This could result in subsequent connections using the same object concurrently which could result in data being returned to the wrong use and/or other errors.

CVSS3: 8.6
0%
Низкий
около 3 лет назад
redhat логотип
CVE-2022-25762

If a web application sends a WebSocket message concurrently with the WebSocket connection closing when running on Apache Tomcat 8.5.0 to 8.5.75 or Apache Tomcat 9.0.0.M1 to 9.0.20, it is possible that the application will continue to use the socket after it has been closed. The error handling triggered in this case could cause the a pooled object to be placed in the pool twice. This could result in subsequent connections using the same object concurrently which could result in data being returned to the wrong use and/or other errors.

CVSS3: 8.6
0%
Низкий
около 3 лет назад
nvd логотип
CVE-2022-25762

If a web application sends a WebSocket message concurrently with the WebSocket connection closing when running on Apache Tomcat 8.5.0 to 8.5.75 or Apache Tomcat 9.0.0.M1 to 9.0.20, it is possible that the application will continue to use the socket after it has been closed. The error handling triggered in this case could cause the a pooled object to be placed in the pool twice. This could result in subsequent connections using the same object concurrently which could result in data being returned to the wrong use and/or other errors.

CVSS3: 8.6
0%
Низкий
около 3 лет назад
debian логотип
CVE-2022-25762

If a web application sends a WebSocket message concurrently with the W ...

CVSS3: 8.6
0%
Низкий
около 3 лет назад
github логотип
GHSA-h3ch-5pp2-vh6w

Improper socket reuse in Apache Tomcat

CVSS3: 8.6
0%
Низкий
около 3 лет назад
fstec логотип
BDU:2022-03062

Уязвимость сервера приложений Apache Tomcat, связанная с ошибками при одновременном закрытии соединения WebSocket и отправки сообщения WebSocket, позволяющая нарушителю раскрыть защищаемую информацию или оказать другое воздействие

CVSS3: 8.6
0%
Низкий
больше 3 лет назад
rocky логотип
RLSA-2020:4847

Moderate: pki-core:10.6 and pki-deps:10.6 security, bug fix, and enhancement update

больше 4 лет назад

Уязвимостей на страницу