CVE-2020-13943
published 2020-10-12CVE-2020-13943: If an HTTP/2 client connecting to Apache Tomcat 10.0.0-M1 to 10.0.0-M7, 9.0.0.M1 to 9.0.37 or 8.5.0 to 8.5.57 exceeded the agreed maximum number of concurrent…
PriorityP339medium4.3CVSS 3.1
AVNACLPRLUINSUCLINAN
EPSS
57.29%
99.0th percentile
If an HTTP/2 client connecting to Apache Tomcat 10.0.0-M1 to 10.0.0-M7, 9.0.0.M1 to 9.0.37 or 8.5.0 to 8.5.57 exceeded the agreed maximum number of concurrent streams for a connection (in violation of the HTTP/2 protocol), it was possible that a subsequent request made on that connection could contain HTTP headers - including HTTP/2 pseudo headers - from a previous request rather than the intended headers. This could lead to users seeing responses for unexpected resources.
Affected
105 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Trigger condition: an HTTP/2 client exceeds the agreed maximum number of concurrent streams for a connection, causing subsequent requests on that connection to carry headers (including HTTP/2 pseudo-headers) from a prior request ↗
- →Monitor HTTP/2 connections where the stream count exceeds the server-negotiated maximum; such violations are the prerequisite for exploitation ↗
- →Fix commit for Tomcat 8.5 branch is 9d7def063b47407a09a2f9202beed99f4dcb292a; use for patch-gap detection or diff analysis ↗
- →Fix commit for Tomcat 10.0 branch: 1bbc650cbc3f08d85a1ec6d803c47ae53a84f3bb ↗
- →Fix commit for Tomcat 9.0 branch: 55911430df13f8c9998fbdee1f9716994d2db59b ↗
- ·Vulnerability only affects deployments where HTTP/2 is enabled on Apache Tomcat; environments where HTTP/2 is not supported/configured are not exploitable ↗
- ·Affected version ranges: Tomcat 8.5.0–8.5.57, 9.0.0.M1–9.0.37, 10.0.0-M1–10.0.0-M7; versions outside these ranges are not affected ↗
CVSS provenance
nvdv3.14.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:N
osv4.3MEDIUM
vendor_apache4.3MEDIUM
vendor_debian4.3MEDIUM
vendor_redhat4.3MEDIUM
vendor_ubuntu4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
tomcat9 vulnerabilities
osv·2022-03-31·CVSS 4.3
CVE-2020-13943 [MEDIUM] tomcat9 vulnerabilities
tomcat9 vulnerabilities
It was discovered that Tomcat incorrectly performed input verification.
A remote attacker could possibly use this issue to intercept sensitive
information. (CVE-2020-13943, CVE-2020-17527, CVE-2021-25122, CVE-2021-30640)
It was discovered that Tomcat did not properly deserialize untrusted data.
An attacker could possibly use this issue to execute arbitrary code.
(CVE-2020-9484, CVE-2021-33037)
It was discovered that Tomcat did not properly validate the input length. An
attacker could possibly use this to trigger an infinite loop, resulting in a
denial of service. (CVE-2021-25329, CVE-2021-41079)
GHSA
Exposure of Sensitive Information to an Unauthorized Actor in Apache Tomcat
ghsa·2022-02-09
CVE-2020-13943 [MEDIUM] CWE-200 Exposure of Sensitive Information to an Unauthorized Actor in Apache Tomcat
Exposure of Sensitive Information to an Unauthorized Actor in Apache Tomcat
If an HTTP/2 client connecting to Apache Tomcat 10.0.0-M1 to 10.0.0-M7, 9.0.0.M1 to 9.0.37 or 8.5.0 to 8.5.57 exceeded the agreed maximum number of concurrent streams for a connection (in violation of the HTTP/2 protocol), it was possible that a subsequent request made on that connection could contain HTTP headers - including HTTP/2 pseudo headers - from a previous request rather than the intended headers. This could lead to users seeing responses for unexpected resources.
OSV
Exposure of Sensitive Information to an Unauthorized Actor in Apache Tomcat
osv·2022-02-09
CVE-2020-13943 [MEDIUM] Exposure of Sensitive Information to an Unauthorized Actor in Apache Tomcat
Exposure of Sensitive Information to an Unauthorized Actor in Apache Tomcat
If an HTTP/2 client connecting to Apache Tomcat 10.0.0-M1 to 10.0.0-M7, 9.0.0.M1 to 9.0.37 or 8.5.0 to 8.5.57 exceeded the agreed maximum number of concurrent streams for a connection (in violation of the HTTP/2 protocol), it was possible that a subsequent request made on that connection could contain HTTP headers - including HTTP/2 pseudo headers - from a previous request rather than the intended headers. This could lead to users seeing responses for unexpected resources.
OSV
CVE-2020-13943: If an HTTP/2 client connecting to Apache Tomcat 10
osv·2020-10-12·CVSS 4.3
CVE-2020-13943 [MEDIUM] CVE-2020-13943: If an HTTP/2 client connecting to Apache Tomcat 10
If an HTTP/2 client connecting to Apache Tomcat 10.0.0-M1 to 10.0.0-M7, 9.0.0.M1 to 9.0.37 or 8.5.0 to 8.5.57 exceeded the agreed maximum number of concurrent streams for a connection (in violation of the HTTP/2 protocol), it was possible that a subsequent request made on that connection could contain HTTP headers - including HTTP/2 pseudo headers - from a previous request rather than the intended headers. This could lead to users seeing responses for unexpected resources.
Ubuntu
Tomcat vulnerabilities
vendor_ubuntu·2022-03-31·CVSS 4.3
CVE-2021-33037 [MEDIUM] Tomcat vulnerabilities
Title: Tomcat vulnerabilities
Summary: Several security issues were fixed in Tomcat.
It was discovered that Tomcat incorrectly performed input verification.
A remote attacker could possibly use this issue to intercept sensitive
information. (CVE-2020-13943, CVE-2020-17527, CVE-2021-25122, CVE-2021-30640)
It was discovered that Tomcat did not properly deserialize untrusted data.
An attacker could possibly use this issue to execute arbitrary code.
(CVE-2020-9484, CVE-2021-33037)
It was discovered that Tomcat did not properly validate the input length. An
attacker could possibly use this to trigger an infinite loop, resulting in a
denial of service. (CVE-2021-25329, CVE-2021-41079)
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
tomcat: Apache Tomcat HTTP/2 Request mix-up
vendor_redhat·2020-10-12·CVSS 4.3
CVE-2020-13943 [MEDIUM] CWE-200 tomcat: Apache Tomcat HTTP/2 Request mix-up
tomcat: Apache Tomcat HTTP/2 Request mix-up
If an HTTP/2 client connecting to Apache Tomcat 10.0.0-M1 to 10.0.0-M7, 9.0.0.M1 to 9.0.37 or 8.5.0 to 8.5.57 exceeded the agreed maximum number of concurrent streams for a connection (in violation of the HTTP/2 protocol), it was possible that a subsequent request made on that connection could contain HTTP headers - including HTTP/2 pseudo headers - from a previous request rather than the intended headers. This could lead to users seeing responses for unexpected resources.
A flaw was found in Apache Tomcat. If an HTTP/2 client exceeded the agreed maximum number of concurrent streams for a connection (in violation of the HTTP/2 protocol), it is possible that a subsequent request made on that connection could contain HTTP headers - including HTTP
Debian
CVE-2020-13943: tomcat9 - If an HTTP/2 client connecting to Apache Tomcat 10.0.0-M1 to 10.0.0-M7, 9.0.0.M1...
vendor_debian·2020·CVSS 4.3
CVE-2020-13943 [MEDIUM] CVE-2020-13943: tomcat9 - If an HTTP/2 client connecting to Apache Tomcat 10.0.0-M1 to 10.0.0-M7, 9.0.0.M1...
If an HTTP/2 client connecting to Apache Tomcat 10.0.0-M1 to 10.0.0-M7, 9.0.0.M1 to 9.0.37 or 8.5.0 to 8.5.57 exceeded the agreed maximum number of concurrent streams for a connection (in violation of the HTTP/2 protocol), it was possible that a subsequent request made on that connection could contain HTTP headers - including HTTP/2 pseudo headers - from a previous request rather than the intended headers. This could lead to users seeing responses for unexpected resources.
Scope: local
bookworm: resolved (fixed in 9.0.38-1)
bullseye: resolved (fixed in 9.0.38-1)
forky: resolved (fixed in 9.0.38-1)
sid: resolved (fixed in 9.0.38-1)
trixie: resolved (fixed in 9.0.38-1)
Apache
Apache tomcat: CVE-2020-13943
vendor_apache·CVSS 4.3
CVE-2020-13943 [MEDIUM] Apache tomcat: CVE-2020-13943
Apache tomcat: CVE-2020-13943
If an HTTP/2 client exceeded the agreed maximum number of concurrent streams for a connection (in violation of the HTTP/2 protocol), it was possible that a subsequent request made on that connection could contain HTTP headers - including HTTP/2 pseudo headers - from a previous request rather than the intended headers. This could lead to users seeing responses for unexpected resources. This was fixed with commit 9d7def06 . This issue was identified by the Apache Tomcat Security team on 23 July 2020. The issue was made public on 12 October 2020. Affects: 8.5.0 to 8.5.57 5 July 2020 Fixed in Apache Tomcat 8.5.57 Important: WebSocket DoS
No detection rules found.
No public exploits indexed.
http://lists.opensuse.org/opensuse-security-announce/2020-11/msg00002.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-11/msg00021.htmlhttps://lists.apache.org/thread.html/r4a390027eb27e4550142fac6c8317cc684b157ae314d31514747f307%40%3Cannounce.tomcat.apache.org%3Ehttps://lists.debian.org/debian-lts-announce/2020/10/msg00019.htmlhttps://security.netapp.com/advisory/ntap-20201016-0007/https://www.debian.org/security/2021/dsa-4835https://www.oracle.com/security-alerts/cpuApr2021.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-11/msg00002.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-11/msg00021.htmlhttps://lists.apache.org/thread.html/r4a390027eb27e4550142fac6c8317cc684b157ae314d31514747f307%40%3Cannounce.tomcat.apache.org%3Ehttps://lists.debian.org/debian-lts-announce/2020/10/msg00019.htmlhttps://security.netapp.com/advisory/ntap-20201016-0007/https://www.debian.org/security/2021/dsa-4835https://www.oracle.com/security-alerts/cpuApr2021.html
2020-10-12
Published