Severity
7.5HIGH
EPSS
23.4%
top 4.04%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 14
Latest updateFeb 8

Description

An h2c direct connection to Apache Tomcat 10.0.0-M1 to 10.0.0-M6, 9.0.0.M5 to 9.0.36 and 8.5.1 to 8.5.56 did not release the HTTP/1.1 processor after the upgrade to HTTP/2. If a sufficient number of such requests were made, an OutOfMemoryException could occur leading to a denial of service.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages16 packages

Mavenorg.apache.tomcat:tomcat10.0.0-M110.0.0-M6+2
NVDapache/tomcat8.5.18.5.56+3
CVEListV5apache_tomcatApache Tomcat 10.0.0-M1 to 10.0.0-M6, 9.0.0.M5 to 9.0.36, 8.5.1 to 8.5.56
Debiantomcat9< 9.0.37-1+3
Ubuntutomcat9< 9.0.31-1ubuntu0.1

Also affects: Debian Linux 10.0, 9.0, Ubuntu Linux 20.04

Patches

🔴Vulnerability Details

5
GHSA
Improper Restriction of Operations within the Bounds of a Memory Buffer in Apache Tomcat2022-02-08
OSV
Improper Restriction of Operations within the Bounds of a Memory Buffer in Apache Tomcat2022-02-08
OSV
tomcat9 vulnerabilities2020-10-21
OSV
CVE-2020-13934: An h2c direct connection to Apache Tomcat 102020-07-14
CVEList
CVE-2020-13934: An h2c direct connection to Apache Tomcat 102020-07-14

📋Vendor Advisories

4
Ubuntu
Tomcat vulnerabilities2020-10-21
Red Hat
tomcat: OutOfMemoryException caused by HTTP/2 connection leak could lead to DoS2020-07-15
Debian
CVE-2020-13934: tomcat9 - An h2c direct connection to Apache Tomcat 10.0.0-M1 to 10.0.0-M6, 9.0.0.M5 to 9....2020
Apache
Apache tomcat: CVE-2020-13934

💬Community

2
Bugzilla
CVE-2020-13934 tomcat: OutOfMemoryException caused by HTTP/2 connection leak could lead to DoS [fedora-all]2020-08-10
Bugzilla
CVE-2020-13934 tomcat: OutOfMemoryException caused by HTTP/2 connection leak could lead to DoS2020-07-15
CVE-2020-13934 (HIGH CVSS 7.5) | An h2c direct connection to Apache | cvebase.io