cbcvebase.
CVE-2020-13943
published 2020-10-12

CVE-2020-13943: If an HTTP/2 client connecting to Apache Tomcat 10.0.0-M1 to 10.0.0-M7, 9.0.0.M1 to 9.0.37 or 8.5.0 to 8.5.57 exceeded the agreed maximum number of concurrent…

PriorityP339medium4.3CVSS 3.1
AVNACLPRLUINSUCLINAN
EPSS
57.29%
99.0th percentile
If an HTTP/2 client connecting to Apache Tomcat 10.0.0-M1 to 10.0.0-M7, 9.0.0.M1 to 9.0.37 or 8.5.0 to 8.5.57 exceeded the agreed maximum number of concurrent streams for a connection (in violation of the HTTP/2 protocol), it was possible that a subsequent request made on that connection could contain HTTP headers - including HTTP/2 pseudo headers - from a previous request rather than the intended headers. This could lead to users seeing responses for unexpected resources.

Affected

105 ranges· showing 25
VendorProductVersion rangeFixed in
apachetomcat
apachetomcat
apachetomcat
apachetomcat
apachetomcat
apachetomcat
apachetomcat
apachetomcat
apachetomcat
apachetomcat
apachetomcat
apachetomcat
apachetomcat
apachetomcat
apachetomcat
apachetomcat
apachetomcat
apachetomcat
apachetomcat
apachetomcat
apachetomcat
apachetomcat
apachetomcat
apachetomcat
apachetomcat

Detection & IOCsextracted from sources · hover to see the quote

  • Trigger condition: an HTTP/2 client exceeds the agreed maximum number of concurrent streams for a connection, causing subsequent requests on that connection to carry headers (including HTTP/2 pseudo-headers) from a prior request
  • Monitor HTTP/2 connections where the stream count exceeds the server-negotiated maximum; such violations are the prerequisite for exploitation
  • Fix commit for Tomcat 8.5 branch is 9d7def063b47407a09a2f9202beed99f4dcb292a; use for patch-gap detection or diff analysis
  • Fix commit for Tomcat 10.0 branch: 1bbc650cbc3f08d85a1ec6d803c47ae53a84f3bb
  • Fix commit for Tomcat 9.0 branch: 55911430df13f8c9998fbdee1f9716994d2db59b
  • ·Vulnerability only affects deployments where HTTP/2 is enabled on Apache Tomcat; environments where HTTP/2 is not supported/configured are not exploitable
  • ·Affected version ranges: Tomcat 8.5.0–8.5.57, 9.0.0.M1–9.0.37, 10.0.0-M1–10.0.0-M7; versions outside these ranges are not affected

CVSS provenance

nvdv3.14.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:N
osv4.3MEDIUM
vendor_apache4.3MEDIUM
vendor_debian4.3MEDIUM
vendor_redhat4.3MEDIUM
vendor_ubuntu4.3MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.