CVE-2020-9494
published 2020-06-24CVE-2020-9494: Apache Traffic Server 6.0.0 to 6.2.3, 7.0.0 to 7.1.10, and 8.0.0 to 8.0.7 is vulnerable to certain types of HTTP/2 HEADERS frames that can cause the server to…
PriorityP339high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
3.91%
89.1th percentile
Apache Traffic Server 6.0.0 to 6.2.3, 7.0.0 to 7.1.10, and 8.0.0 to 8.0.7 is vulnerable to certain types of HTTP/2 HEADERS frames that can cause the server to allocate a large amount of memory and spin the thread.
Affected
32 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | 7.0.0 – 7.0.107 | — |
| apache | tomcat | 8.5.0 – 8.5.61 | — |
| apache | tomcat | 9.0.0 – 9.0.41 | — |
| apache | traffic_server | 6.0.0 – 6.2.3 | — |
| apache | traffic_server | 7.0.0 – 7.1.10 | — |
| apache | traffic_server | 8.0.0 – 8.0.7 | — |
| apache_software_foundation | apache_traffic_server | — | — |
| apache_software_foundation | apache_traffic_server | — | — |
| apache_software_foundation | apache_traffic_server | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | tomcat9 | < tomcat9 9.0.43-1 (bookworm) | tomcat9 9.0.43-1 (bookworm) |
| debian | trafficserver | < trafficserver 8.0.8+ds-1 (bookworm) | trafficserver 8.0.8+ds-1 (bookworm) |
| oracle | agile_plm | — | — |
| oracle | agile_plm | — | — |
| oracle | communications_cloud_native_core_policy | — | — |
| oracle | communications_cloud_native_core_security_edge_protection_proxy | — | — |
| oracle | communications_instant_messaging_server | — | — |
| oracle | database | — | — |
| oracle | database | — | — |
| oracle | database | — | — |
| oracle | graph_server_and_client | < 21.3.0 | 21.3.0 |
| oracle | instantis_enterprisetrack | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
ghsa7.0HIGH
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.0HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-cw5m-934f-xqmc: Apache Traffic Server 6
ghsa_unreviewed·2022-05-24
CVE-2020-9494 [MEDIUM] CWE-119 GHSA-cw5m-934f-xqmc: Apache Traffic Server 6
Apache Traffic Server 6.0.0 to 6.2.3, 7.0.0 to 7.1.10, and 8.0.0 to 8.0.7 is vulnerable to certain types of HTTP/2 HEADERS frames that can cause the server to allocate a large amount of memory and spin the thread.
GHSA
Potential remote code execution in Apache Tomcat
ghsa·2021-03-19·CVSS 7.0
CVE-2021-25329 [HIGH] CWE-502 Potential remote code execution in Apache Tomcat
Potential remote code execution in Apache Tomcat
The fix for CVE-2020-9484 was incomplete. When using Apache Tomcat 10.0.0-M1 to 10.0.0, 9.0.0.M1 to 9.0.41, 8.5.0 to 8.5.61 or 7.0.0. to 7.0.107 with a configuration edge case that was highly unlikely to be used, the Tomcat instance was still vulnerable to CVE-2020-9494. Note that both the previously published prerequisites for CVE-2020-9484 and the previously published mitigations for CVE-2020-9484 also apply to this issue.
OSV
Potential remote code execution in Apache Tomcat
osv·2021-03-19·CVSS 7.0
CVE-2021-25329 [HIGH] Potential remote code execution in Apache Tomcat
Potential remote code execution in Apache Tomcat
The fix for CVE-2020-9484 was incomplete. When using Apache Tomcat 10.0.0-M1 to 10.0.0, 9.0.0.M1 to 9.0.41, 8.5.0 to 8.5.61 or 7.0.0. to 7.0.107 with a configuration edge case that was highly unlikely to be used, the Tomcat instance was still vulnerable to CVE-2020-9494. Note that both the previously published prerequisites for CVE-2020-9484 and the previously published mitigations for CVE-2020-9484 also apply to this issue.
OSV
CVE-2021-25329: The fix for CVE-2020-9484 was incomplete
osv·2021-03-01·CVSS 7.0
CVE-2021-25329 [HIGH] CVE-2021-25329: The fix for CVE-2020-9484 was incomplete
The fix for CVE-2020-9484 was incomplete. When using Apache Tomcat 10.0.0-M1 to 10.0.0, 9.0.0.M1 to 9.0.41, 8.5.0 to 8.5.61 or 7.0.0. to 7.0.107 with a configuration edge case that was highly unlikely to be used, the Tomcat instance was still vulnerable to CVE-2020-9494. Note that both the previously published prerequisites for CVE-2020-9484 and the previously published mitigations for CVE-2020-9484 also apply to this issue.
OSV
CVE-2020-9494: Apache Traffic Server 6
osv·2020-06-24·CVSS 7.5
CVE-2020-9494 [HIGH] CVE-2020-9494: Apache Traffic Server 6
Apache Traffic Server 6.0.0 to 6.2.3, 7.0.0 to 7.1.10, and 8.0.0 to 8.0.7 is vulnerable to certain types of HTTP/2 HEADERS frames that can cause the server to allocate a large amount of memory and spin the thread.
Red Hat
tomcat: Incomplete fix for CVE-2020-9484 (RCE via session persistence)
vendor_redhat·2021-03-01·CVSS 7.0
CVE-2021-25329 [HIGH] CWE-502 tomcat: Incomplete fix for CVE-2020-9484 (RCE via session persistence)
tomcat: Incomplete fix for CVE-2020-9484 (RCE via session persistence)
The fix for CVE-2020-9484 was incomplete. When using Apache Tomcat 10.0.0-M1 to 10.0.0, 9.0.0.M1 to 9.0.41, 8.5.0 to 8.5.61 or 7.0.0. to 7.0.107 with a configuration edge case that was highly unlikely to be used, the Tomcat instance was still vulnerable to CVE-2020-9494. Note that both the previously published prerequisites for CVE-2020-9484 and the previously published mitigations for CVE-2020-9484 also apply to this issue.
Statement: In Red Hat Enterprise Linux 8, Red Hat Certificate System 10 and Identity Management are using the `pki-servlet-engine` component, which embeds a vulnerable version of Tomcat. However, in these specific contexts, the prerequisites to the vulnerability are not met. The PersistentManager
Debian
CVE-2021-25329: tomcat9 - The fix for CVE-2020-9484 was incomplete. When using Apache Tomcat 10.0.0-M1 to ...
vendor_debian·2021·CVSS 7.0
CVE-2021-25329 [HIGH] CVE-2021-25329: tomcat9 - The fix for CVE-2020-9484 was incomplete. When using Apache Tomcat 10.0.0-M1 to ...
The fix for CVE-2020-9484 was incomplete. When using Apache Tomcat 10.0.0-M1 to 10.0.0, 9.0.0.M1 to 9.0.41, 8.5.0 to 8.5.61 or 7.0.0. to 7.0.107 with a configuration edge case that was highly unlikely to be used, the Tomcat instance was still vulnerable to CVE-2020-9494. Note that both the previously published prerequisites for CVE-2020-9484 and the previously published mitigations for CVE-2020-9484 also apply to this issue.
Scope: local
bookworm: resolved (fixed in 9.0.43-1)
bullseye: resolved (fixed in 9.0.43-1)
forky: resolved (fixed in 9.0.43-1)
sid: resolved (fixed in 9.0.43-1)
trixie: resolved (fixed in 9.0.43-1)
Debian
CVE-2020-9494: trafficserver - Apache Traffic Server 6.0.0 to 6.2.3, 7.0.0 to 7.1.10, and 8.0.0 to 8.0.7 is vul...
vendor_debian·2020·CVSS 7.5
CVE-2020-9494 [HIGH] CVE-2020-9494: trafficserver - Apache Traffic Server 6.0.0 to 6.2.3, 7.0.0 to 7.1.10, and 8.0.0 to 8.0.7 is vul...
Apache Traffic Server 6.0.0 to 6.2.3, 7.0.0 to 7.1.10, and 8.0.0 to 8.0.7 is vulnerable to certain types of HTTP/2 HEADERS frames that can cause the server to allocate a large amount of memory and spin the thread.
Scope: local
bookworm: resolved (fixed in 8.0.8+ds-1)
bullseye: resolved (fixed in 8.0.8+ds-1)
sid: resolved (fixed in 8.0.8+ds-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.openwall.com/lists/oss-security/2021/03/01/2https://lists.apache.org/thread.html/rf7f86917f42fdaf904d99560cba0c016e03baea6244c47efeb60ecbe%40%3Cdev.trafficserver.apache.org%3Ehttps://www.debian.org/security/2020/dsa-4710http://www.openwall.com/lists/oss-security/2021/03/01/2https://lists.apache.org/thread.html/rf7f86917f42fdaf904d99560cba0c016e03baea6244c47efeb60ecbe%40%3Cdev.trafficserver.apache.org%3Ehttps://www.debian.org/security/2020/dsa-4710
2020-06-24
Published