CVE-2018-8037Race Condition in Apache Tomcat

CWE-362Race Condition13 documents8 sources
Severity
5.9MEDIUMNVD
EPSS
8.4%
top 7.64%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 2
Latest updateApr 11

Description

If an async request was completed by the application at the same time as the container triggered the async timeout, a race condition existed that could result in a user seeing a response intended for a different user. An additional issue was present in the NIO and NIO2 connectors that did not correctly track the closure of the connection when an async request was completed by the application and timed out by the container at the same time. This could also result in a user seeing a response inten

CVSS vector

CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 2.2 | Impact: 3.6

Affected Packages2 packages

NVDapache/tomcat8.5.58.5.31+2
CVEListV5apache_software_foundation/apache_tomcat8.5.5 to 8.5.31, 9.0.0.M9 to 9.0.9+1

Also affects: Debian Linux 9.0

Patches

🔴Vulnerability Details

6
OSV
tcpdump vulnerabilities2022-04-11
OSV
tcpdump vulnerabilities2022-03-16
OSV
Apache Tomcat Race Condition vulnerability2018-10-17
GHSA
Apache Tomcat Race Condition vulnerability2018-10-17
CVEList
CVE-2018-8037: If an async request was completed by the application at the same time as the container triggered the async timeout, a race condition existed that coul2018-08-02

📋Vendor Advisories

3
Red Hat
tomcat: Due to a mishandling of close in NIO/NIO2 connectors user sessions can get mixed up2018-07-22
Debian
CVE-2018-8037: tomcat9 - If an async request was completed by the application at the same time as the con...2018
Apache
Apache tomcat: CVE-2018-8037

💬Community

3
Bugzilla
CVE-2018-8037 tomcat: Due to a mishandling of close in NIO/NIO2 connectors user sessions can get mixed up2018-07-23
Bugzilla
CVE-2018-8037 tomcat: Due to a mishandling of close in NIO/NIO2 connectors user sessions can get mixed up [fedora-all]2018-07-23
Bugzilla
CVE-2018-8037 tomcat: Due to a mishandling of close in NIO/NIO2 connectors user sessions can get mixed up [epel-all]2018-07-23
CVE-2018-8037 — Race Condition in Apache Tomcat | cvebase