CVE-2021-43980
published 2022-09-28CVE-2021-43980: The simplified implementation of blocking reads and writes introduced in Tomcat 10 and back-ported to Tomcat 9.0.47 onwards exposed a long standing (but…
PriorityP417low3.7CVSS 3.1
AVNACHPRNUINSUCLINAN
EPSS
1.91%
77.6th percentile
The simplified implementation of blocking reads and writes introduced in Tomcat 10 and back-ported to Tomcat 9.0.47 onwards exposed a long standing (but extremely hard to trigger) concurrency bug in Apache Tomcat 10.1.0 to 10.1.0-M12, 10.0.0-M1 to 10.0.18, 9.0.0-M1 to 9.0.60 and 8.5.0 to 8.5.77 that could cause client connections to share an Http11Processor instance resulting in responses, or part responses, to be received by the wrong client.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | 10.0.0 – 10.0.18 | — |
| apache | tomcat | 8.5.0 – 8.5.77 | — |
| apache | tomcat | 9.0.0 – 9.0.60 | — |
| apache_software_foundation | apache_tomcat | — | — |
| apache_software_foundation | apache_tomcat | — | — |
| apache_software_foundation | apache_tomcat | — | — |
| apache_software_foundation | apache_tomcat | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | tomcat9 | < tomcat9 9.0.62-1 (bookworm) | tomcat9 9.0.62-1 (bookworm) |
CVSS provenance
nvdv3.13.7LOWCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
osv3.7LOW
vendor_apache3.7LOW
vendor_debian3.7LOW
vendor_redhat3.7LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
Tomcat: Information disclosure
vendor_redhat·2022-09-28·CVSS 3.7
CVE-2021-43980 [LOW] Tomcat: Information disclosure
Tomcat: Information disclosure
The simplified implementation of blocking reads and writes introduced in Tomcat 10 and back-ported to Tomcat 9.0.47 onwards exposed a long standing (but extremely hard to trigger) concurrency bug in Apache Tomcat 10.1.0 to 10.1.0-M12, 10.0.0-M1 to 10.0.18, 9.0.0-M1 to 9.0.60 and 8.5.0 to 8.5.77 that could cause client connections to share an Http11Processor instance resulting in responses, or part responses, to be received by the wrong client.
Statement: Red Hat Satellite does not include the affected Apache Tomcat, however, Tomcat is shipped with Red Hat Enterprise Linux and consumed by the Candlepin component of Satellite. Red Hat Satellite users are therefore advised to check the impact state of Red Hat Enterprise Linux, since any necessary fixes will be
Debian
CVE-2021-43980: tomcat9 - The simplified implementation of blocking reads and writes introduced in Tomcat ...
vendor_debian·2021·CVSS 3.7
CVE-2021-43980 [LOW] CVE-2021-43980: tomcat9 - The simplified implementation of blocking reads and writes introduced in Tomcat ...
The simplified implementation of blocking reads and writes introduced in Tomcat 10 and back-ported to Tomcat 9.0.47 onwards exposed a long standing (but extremely hard to trigger) concurrency bug in Apache Tomcat 10.1.0 to 10.1.0-M12, 10.0.0-M1 to 10.0.18, 9.0.0-M1 to 9.0.60 and 8.5.0 to 8.5.77 that could cause client connections to share an Http11Processor instance resulting in responses, or part responses, to be received by the wrong client.
Scope: local
bookworm: resolved (fixed in 9.0.62-1)
bullseye: resolved (fixed in 9.0.43-2~deb11u4)
forky: resolved (fixed in 9.0.62-1)
sid: resolved (fixed in 9.0.62-1)
trixie: resolved (fixed in 9.0.62-1)
Apache
Apache tomcat: CVE-2021-43980
vendor_apache·CVSS 3.7
CVE-2021-43980 [LOW] Apache tomcat: CVE-2021-43980
Apache tomcat: CVE-2021-43980
The simplified implementation of blocking reads and writes introduced in Tomcat 10 and back-ported to Tomcat 9.0.47 onwards exposed a long standing (but extremely hard to trigger) concurrency bug that could cause client connections to share an Http11Processor instance resulting in responses, or part responses, to be received by the wrong client. This was fixed with commit 4a00b0c0 . This issue was reported to the Apache Tomcat Security team by Adam Thomas, Richard Hernandez and Ryan Schmitt on 11 November 2021. The issue was made public on 28 September 2022. Affects: 8.5.0 to 8.5.77 28 February 2022 Fixed in Apache Tomcat 8.5.76 Important: Request mix-up
GHSA
Apache Tomcat Race Condition vulnerability
ghsa·2022-09-29
CVE-2021-43980 [LOW] CWE-362 Apache Tomcat Race Condition vulnerability
Apache Tomcat Race Condition vulnerability
The simplified implementation of blocking reads and writes introduced in Tomcat 10 and back-ported to Tomcat 9.0.47 onwards exposed a long standing (but extremely hard to trigger) concurrency bug in Apache Tomcat 10.1.0 to 10.1.0-M12, 10.0.0-M1 to 10.0.18, 9.0.0-M1 to 9.0.60 and 8.5.0 to 8.5.77 that could cause client connections to share an Http11Processor instance resulting in responses, or part responses, to be received by the wrong client.
OSV
Apache Tomcat Race Condition vulnerability
osv·2022-09-29
CVE-2021-43980 [LOW] Apache Tomcat Race Condition vulnerability
Apache Tomcat Race Condition vulnerability
The simplified implementation of blocking reads and writes introduced in Tomcat 10 and back-ported to Tomcat 9.0.47 onwards exposed a long standing (but extremely hard to trigger) concurrency bug in Apache Tomcat 10.1.0 to 10.1.0-M12, 10.0.0-M1 to 10.0.18, 9.0.0-M1 to 9.0.60 and 8.5.0 to 8.5.77 that could cause client connections to share an Http11Processor instance resulting in responses, or part responses, to be received by the wrong client.
OSV
CVE-2021-43980: The simplified implementation of blocking reads and writes introduced in Tomcat 10 and back-ported to Tomcat 9
osv·2022-09-28·CVSS 3.7
CVE-2021-43980 [LOW] CVE-2021-43980: The simplified implementation of blocking reads and writes introduced in Tomcat 10 and back-ported to Tomcat 9
The simplified implementation of blocking reads and writes introduced in Tomcat 10 and back-ported to Tomcat 9.0.47 onwards exposed a long standing (but extremely hard to trigger) concurrency bug in Apache Tomcat 10.1.0 to 10.1.0-M12, 10.0.0-M1 to 10.0.18, 9.0.0-M1 to 9.0.60 and 8.5.0 to 8.5.77 that could cause client connections to share an Http11Processor instance resulting in responses, or part responses, to be received by the wrong client.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.openwall.com/lists/oss-security/2022/09/28/1https://lists.apache.org/thread/3jjqbsp6j88b198x5rmg99b1qr8ht3g3https://lists.debian.org/debian-lts-announce/2022/10/msg00029.htmlhttps://www.debian.org/security/2022/dsa-5265http://www.openwall.com/lists/oss-security/2022/09/28/1https://lists.apache.org/thread/3jjqbsp6j88b198x5rmg99b1qr8ht3g3https://lists.debian.org/debian-lts-announce/2022/10/msg00029.htmlhttps://www.debian.org/security/2022/dsa-5265
2022-09-28
Published