CVE-2020-17527
published 2020-12-03CVE-2020-17527: While investigating bug 64830 it was discovered that Apache Tomcat 10.0.0-M1 to 10.0.0-M9, 9.0.0-M1 to 9.0.39 and 8.5.0 to 8.5.59 could re-use an HTTP request…
PriorityP353high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
EPSS
24.62%
97.7th percentile
While investigating bug 64830 it was discovered that Apache Tomcat 10.0.0-M1 to 10.0.0-M9, 9.0.0-M1 to 9.0.39 and 8.5.0 to 8.5.59 could re-use an HTTP request header value from the previous stream received on an HTTP/2 connection for the request associated with the subsequent stream. While this would most likely lead to an error and the closure of the HTTP/2 connection, it is possible that information could leak between requests.
Affected
31 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | 8.5.1 – 8.5.59 | — |
| apache | tomcat | 9.0.1 – 9.0.35 | — |
| apache_software_foundation | apache_tomcat | — | — |
| apache_software_foundation | apache_tomcat | — | — |
| apache_software_foundation | apache_tomcat | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | tomcat9 | < tomcat9 9.0.40-1 (bookworm) | tomcat9 9.0.40-1 (bookworm) |
| msrc | cbl2_tomcat_9.0.39-5_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_tomcat_9.0.39-6_on_cbl_mariner_2.0 | — | — |
| netapp | oncommand_system_manager | 3.0.0 – 3.1.3 | — |
| oracle | blockchain_platform | < 21.1.2 | 21.1.2 |
| oracle | communications_cloud_native_core_binding_support_function | — | — |
| oracle | communications_cloud_native_core_policy | — | — |
| oracle | communications_instant_messaging_server | — | — |
| oracle | instantis_enterprisetrack | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
osv7.5HIGH
vendor_apache7.5HIGH
vendor_debian7.5HIGH
vendor_msrc7.5HIGH
vendor_oracle7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Oracle
Oracle Oracle Blockchain Platform Risk Matrix: BCS Console (Apache Tomcat) — CVE-2020-17527
vendor_oracle·2022-04-15·CVSS 7.5
CVE-2020-17527 [HIGH] Oracle Oracle Blockchain Platform Risk Matrix: BCS Console (Apache Tomcat) — CVE-2020-17527
Oracle Oracle Blockchain Platform Risk Matrix: BCS Console (Apache Tomcat) vulnerability
CVE: CVE-2020-17527
CVSS: 7.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuapr2022 (APR 2022)
Ubuntu
Tomcat vulnerabilities
vendor_ubuntu·2022-03-31·CVSS 4.3
CVE-2021-33037 [MEDIUM] Tomcat vulnerabilities
Title: Tomcat vulnerabilities
Summary: Several security issues were fixed in Tomcat.
It was discovered that Tomcat incorrectly performed input verification.
A remote attacker could possibly use this issue to intercept sensitive
information. (CVE-2020-13943, CVE-2020-17527, CVE-2021-25122, CVE-2021-30640)
It was discovered that Tomcat did not properly deserialize untrusted data.
An attacker could possibly use this issue to execute arbitrary code.
(CVE-2020-9484, CVE-2021-33037)
It was discovered that Tomcat did not properly validate the input length. An
attacker could possibly use this to trigger an infinite loop, resulting in a
denial of service. (CVE-2021-25329, CVE-2021-41079)
Instructions: In general, a standard system update will make all the necessary changes.
Oracle
Oracle Oracle Communications Risk Matrix: Binding Support Function (Apache Tomcat) — CVE-2020-17527
vendor_oracle·2022-01-15·CVSS 7.5
CVE-2020-17527 [HIGH] Oracle Oracle Communications Risk Matrix: Binding Support Function (Apache Tomcat) — CVE-2020-17527
Oracle Oracle Communications Risk Matrix: Binding Support Function (Apache Tomcat) vulnerability
CVE: CVE-2020-17527
CVSS: 7.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujan2022 (JAN 2022)
Oracle
Oracle Oracle Big Data Graph Risk Matrix: Big Data Graph (Apache Tomcat) — CVE-2020-17527
vendor_oracle·2021-07-15·CVSS 7.5
CVE-2020-17527 [HIGH] Oracle Oracle Big Data Graph Risk Matrix: Big Data Graph (Apache Tomcat) — CVE-2020-17527
Oracle Oracle Big Data Graph Risk Matrix: Big Data Graph (Apache Tomcat) vulnerability
CVE: CVE-2020-17527
CVSS: 7.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujul2021 (JUL 2021)
Oracle
Oracle Oracle Database Server Risk Matrix: Workload Manager (Apache Tomcat) — CVE-2020-17527
vendor_oracle·2021-04-15·CVSS 7.5
CVE-2020-17527 [HIGH] Oracle Oracle Database Server Risk Matrix: Workload Manager (Apache Tomcat) — CVE-2020-17527
Oracle Oracle Database Server Risk Matrix: Workload Manager (Apache Tomcat) vulnerability
CVE: CVE-2020-17527
CVSS: 7.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuapr2021 (APR 2021)
Microsoft
Apache Tomcat: Request header mix-up between HTTP/2 streams
vendor_msrc·2020-12-08·CVSS 7.5
CVE-2020-17527 [HIGH] CWE-200 Apache Tomcat: Request header mix-up between HTTP/2 streams
Apache Tomcat: Request header mix-up between HTTP/2 streams
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
apache: apache
Customer Action Required: Yes
Remediation: CBL-Mariner Releases
Reference: https:/
Red Hat
tomcat: HTTP/2 request header mix-up
vendor_redhat·2020-12-03·CVSS 7.5
CVE-2020-17527 [HIGH] CWE-200 tomcat: HTTP/2 request header mix-up
tomcat: HTTP/2 request header mix-up
While investigating bug 64830 it was discovered that Apache Tomcat 10.0.0-M1 to 10.0.0-M9, 9.0.0-M1 to 9.0.39 and 8.5.0 to 8.5.59 could re-use an HTTP request header value from the previous stream received on an HTTP/2 connection for the request associated with the subsequent stream. While this would most likely lead to an error and the closure of the HTTP/2 connection, it is possible that information could leak between requests.
Statement: Red Hat Enterprise Linux 8's Identity Management and Certificate System are using a vulnerable version of Tomcat that is bundled into the pki-servlet-engine component. However, HTTP/2 is not enabled in such a configuration, and it is not possible to trigger the flaw in a supported setup. A future update may fix the
Debian
CVE-2020-17527: tomcat9 - While investigating bug 64830 it was discovered that Apache Tomcat 10.0.0-M1 to ...
vendor_debian·2020·CVSS 7.5
CVE-2020-17527 [HIGH] CVE-2020-17527: tomcat9 - While investigating bug 64830 it was discovered that Apache Tomcat 10.0.0-M1 to ...
While investigating bug 64830 it was discovered that Apache Tomcat 10.0.0-M1 to 10.0.0-M9, 9.0.0-M1 to 9.0.39 and 8.5.0 to 8.5.59 could re-use an HTTP request header value from the previous stream received on an HTTP/2 connection for the request associated with the subsequent stream. While this would most likely lead to an error and the closure of the HTTP/2 connection, it is possible that information could leak between requests.
Scope: local
bookworm: resolved (fixed in 9.0.40-1)
bullseye: resolved (fixed in 9.0.40-1)
forky: resolved (fixed in 9.0.40-1)
sid: resolved (fixed in 9.0.40-1)
trixie: resolved (fixed in 9.0.40-1)
Apache
Apache tomcat: CVE-2020-17527
vendor_apache·CVSS 7.5
CVE-2020-17527 [HIGH] Apache tomcat: CVE-2020-17527
Apache tomcat: CVE-2020-17527
While investigating issue 64830 it was discovered that Apache Tomcat could re-use an HTTP request header value from the previous stream received on an HTTP/2 connection for the request associated with the subsequent stream. While this would most likely lead to an error and the closure of the HTTP/2 connection, it is possible that information could leak between requests. This was fixed with commit 21e34086 . This issue was identified by the Apache Tomcat Security team on 10 November 2020. The issue was made public on 3 December 2020. Affects: 8.5.0 to 8.5.59 15 September 2020 Fixed in Apache Tomcat 8.5.58 Moderate: HTTP/2 request mix-up
OSV
tomcat9 vulnerabilities
osv·2022-03-31·CVSS 4.3
CVE-2020-13943 [MEDIUM] tomcat9 vulnerabilities
tomcat9 vulnerabilities
It was discovered that Tomcat incorrectly performed input verification.
A remote attacker could possibly use this issue to intercept sensitive
information. (CVE-2020-13943, CVE-2020-17527, CVE-2021-25122, CVE-2021-30640)
It was discovered that Tomcat did not properly deserialize untrusted data.
An attacker could possibly use this issue to execute arbitrary code.
(CVE-2020-9484, CVE-2021-33037)
It was discovered that Tomcat did not properly validate the input length. An
attacker could possibly use this to trigger an infinite loop, resulting in a
denial of service. (CVE-2021-25329, CVE-2021-41079)
OSV
Exposure of Sensitive Information to an Unauthorized Actor in Apache Tomcat
osv·2022-02-09
CVE-2020-17527 [HIGH] Exposure of Sensitive Information to an Unauthorized Actor in Apache Tomcat
Exposure of Sensitive Information to an Unauthorized Actor in Apache Tomcat
While investigating bug 64830 it was discovered that Apache Tomcat 10.0.0-M1 to 10.0.0-M9, 9.0.0-M1 to 9.0.39 and 8.5.0 to 8.5.59 could re-use an HTTP request header value from the previous stream received on an HTTP/2 connection for the request associated with the subsequent stream. While this would most likely lead to an error and the closure of the HTTP/2 connection, it is possible that information could leak between requests.
GHSA
Exposure of Sensitive Information to an Unauthorized Actor in Apache Tomcat
ghsa·2022-02-09
CVE-2020-17527 [HIGH] CWE-200 Exposure of Sensitive Information to an Unauthorized Actor in Apache Tomcat
Exposure of Sensitive Information to an Unauthorized Actor in Apache Tomcat
While investigating bug 64830 it was discovered that Apache Tomcat 10.0.0-M1 to 10.0.0-M9, 9.0.0-M1 to 9.0.39 and 8.5.0 to 8.5.59 could re-use an HTTP request header value from the previous stream received on an HTTP/2 connection for the request associated with the subsequent stream. While this would most likely lead to an error and the closure of the HTTP/2 connection, it is possible that information could leak between requests.
OSV
CVE-2020-17527: While investigating bug 64830 it was discovered that Apache Tomcat 10
osv·2020-12-03·CVSS 7.5
CVE-2020-17527 [HIGH] CVE-2020-17527: While investigating bug 64830 it was discovered that Apache Tomcat 10
While investigating bug 64830 it was discovered that Apache Tomcat 10.0.0-M1 to 10.0.0-M9, 9.0.0-M1 to 9.0.39 and 8.5.0 to 8.5.59 could re-use an HTTP request header value from the previous stream received on an HTTP/2 connection for the request associated with the subsequent stream. While this would most likely lead to an error and the closure of the HTTP/2 connection, it is possible that information could leak between requests.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2024-4109 undertow: information leakage via HTTP/2 request header reuse
bugzilla·2024-03-30·CVSS 7.5
CVE-2024-4109 [HIGH] CVE-2024-4109 undertow: information leakage via HTTP/2 request header reuse
CVE-2024-4109 undertow: information leakage via HTTP/2 request header reuse
Description:
Product Security received a report that Undertow might incorrectly re-use an HTTP request header value from a previous stream for a request associated with a subsequent stream on the same HTTP/2 connection. The issue is linked to the readHpackString method and its interaction with the stringBuilder field. While such behavior typically results in an error followed by the termination of the HTTP/2 connection, it presents a potential vector for information leakage between requests.
The original reporter referenced a similar issue in Apache Tomcat (CVE-2020-17527). In the patch for that vulnerability (https://github.com/apache/tomcat/commit/8d2fe6894d6e258a6d615d7f786acca80e6020cb) a StringBuilder field
Bugzilla
CVE-2020-17527 tomcat: HTTP/2 request header mix-up
bugzilla·2020-12-03·CVSS 7.5
CVE-2020-17527 [HIGH] CVE-2020-17527 tomcat: HTTP/2 request header mix-up
CVE-2020-17527 tomcat: HTTP/2 request header mix-up
While investigating Bug 64830 it was discovered that Apache Tomcat could re-use an HTTP request header value from the previous stream received on an HTTP/2 connection for the request associated with the subsequent stream. While this would most likely lead to an error and the closure of the HTTP/2 connection, it is possible that information could leak between requests.
Reference:
https://lists.apache.org/thread.html/rce5ac9a40173651d540babce59f6f3825f12c6d4e886ba00823b11e5@%3Cannounce.apache.org%3E
Discussion:
Created tomcat tracking bugs for this issue:
Affects: fedora-all [bug 1904222]
---
This vulnerability is out of security support scope for the following products:
* Red Hat Enterprise Application Platform 6
* Red Hat Data Grid
http://www.openwall.com/lists/oss-security/2020/12/03/3https://lists.apache.org/thread.html/r26a2a66339087fc37db3caf201e446d3e83b5cce314371e235ff1784%40%3Ccommits.tomee.apache.org%3Ehttps://lists.apache.org/thread.html/r2d6e05c5ff96f8068a59dfdb3800e9ee8d4e36ce1971783c6e5f9b20%40%3Ccommits.tomee.apache.org%3Ehttps://lists.apache.org/thread.html/r5a285242737ddef4d338236328aaaf3237183e1465a5efafd16b99ed%40%3Cdev.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/r8a227ac6a755a6406c1cc47dd48800e973d4cf13fe7fe68ac59c679c%40%3Cdev.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/r9fd47f1b03e9b41d16a5cf72659b533887267d3398d963c2fff3abfa%40%3Ccommits.tomee.apache.org%3Ehttps://lists.apache.org/thread.html/ra35c8d617b17d59f400112cebadec43ad379f98198b4a9726190d7ee%40%3Cissues.guacamole.apache.org%3Ehttps://lists.apache.org/thread.html/ra9fcdb904dd2e2256ef90b3e4ced279cd464cb0ab63a6c64df5c010d%40%3Cannounce.apache.org%3Ehttps://lists.apache.org/thread.html/ra9fcdb904dd2e2256ef90b3e4ced279cd464cb0ab63a6c64df5c010d%40%3Cannounce.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/raa0e9ad388c1e6fd1e301b5e080f9439f64cb4178119a86a4801cc53%40%3Cdev.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/rabbe6b3ae6a9795641d7a05c00d2378d5bbbe4240b7e20f09b092cce%40%3Cissues.guacamole.apache.org%3Ehttps://lists.apache.org/thread.html/rbba08c4dcef3603e36276d49adda8eedbe458c5104314b4038f697e1%40%3Cusers.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/rca833c6d42b7b9ce1563488c0929f29fcc95947d86e5e740258c8937%40%3Cdev.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/rce5ac9a40173651d540babce59f6f3825f12c6d4e886ba00823b11e5%40%3Cannounce.apache.org%3Ehttps://lists.apache.org/thread.html/rce5ac9a40173651d540babce59f6f3825f12c6d4e886ba00823b11e5%40%3Cannounce.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/rce5ac9a40173651d540babce59f6f3825f12c6d4e886ba00823b11e5%40%3Cannounce.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/rd5babd13d7a350b369b2f647b4dd32ce678af42f9aba5389df1ae6ca%40%3Cusers.tomcat.apache.org%3Ehttps://lists.debian.org/debian-lts-announce/2020/12/msg00022.htmlhttps://security.gentoo.org/glsa/202012-23https://security.netapp.com/advisory/ntap-20201210-0003/https://www.debian.org/security/2021/dsa-4835https://www.oracle.com//security-alerts/cpujul2021.htmlhttps://www.oracle.com/security-alerts/cpuApr2021.htmlhttps://www.oracle.com/security-alerts/cpuapr2022.htmlhttps://www.oracle.com/security-alerts/cpujan2022.htmlhttp://www.openwall.com/lists/oss-security/2020/12/03/3https://lists.apache.org/thread.html/r26a2a66339087fc37db3caf201e446d3e83b5cce314371e235ff1784%40%3Ccommits.tomee.apache.org%3Ehttps://lists.apache.org/thread.html/r2d6e05c5ff96f8068a59dfdb3800e9ee8d4e36ce1971783c6e5f9b20%40%3Ccommits.tomee.apache.org%3Ehttps://lists.apache.org/thread.html/r5a285242737ddef4d338236328aaaf3237183e1465a5efafd16b99ed%40%3Cdev.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/r8a227ac6a755a6406c1cc47dd48800e973d4cf13fe7fe68ac59c679c%40%3Cdev.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/r9fd47f1b03e9b41d16a5cf72659b533887267d3398d963c2fff3abfa%40%3Ccommits.tomee.apache.org%3Ehttps://lists.apache.org/thread.html/ra35c8d617b17d59f400112cebadec43ad379f98198b4a9726190d7ee%40%3Cissues.guacamole.apache.org%3Ehttps://lists.apache.org/thread.html/ra9fcdb904dd2e2256ef90b3e4ced279cd464cb0ab63a6c64df5c010d%40%3Cannounce.apache.org%3Ehttps://lists.apache.org/thread.html/ra9fcdb904dd2e2256ef90b3e4ced279cd464cb0ab63a6c64df5c010d%40%3Cannounce.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/raa0e9ad388c1e6fd1e301b5e080f9439f64cb4178119a86a4801cc53%40%3Cdev.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/rabbe6b3ae6a9795641d7a05c00d2378d5bbbe4240b7e20f09b092cce%40%3Cissues.guacamole.apache.org%3Ehttps://lists.apache.org/thread.html/rbba08c4dcef3603e36276d49adda8eedbe458c5104314b4038f697e1%40%3Cusers.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/rca833c6d42b7b9ce1563488c0929f29fcc95947d86e5e740258c8937%40%3Cdev.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/rce5ac9a40173651d540babce59f6f3825f12c6d4e886ba00823b11e5%40%3Cannounce.apache.org%3Ehttps://lists.apache.org/thread.html/rce5ac9a40173651d540babce59f6f3825f12c6d4e886ba00823b11e5%40%3Cannounce.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/rce5ac9a40173651d540babce59f6f3825f12c6d4e886ba00823b11e5%40%3Cannounce.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/rd5babd13d7a350b369b2f647b4dd32ce678af42f9aba5389df1ae6ca%40%3Cusers.tomcat.apache.org%3Ehttps://lists.debian.org/debian-lts-announce/2020/12/msg00022.htmlhttps://security.gentoo.org/glsa/202012-23https://security.netapp.com/advisory/ntap-20201210-0003/https://www.debian.org/security/2021/dsa-4835https://www.oracle.com//security-alerts/cpujul2021.htmlhttps://www.oracle.com/security-alerts/cpuApr2021.htmlhttps://www.oracle.com/security-alerts/cpuapr2022.htmlhttps://www.oracle.com/security-alerts/cpujan2022.html
2020-12-03
Published