CVE-2022-25762
published 2022-05-13CVE-2022-25762: If a web application sends a WebSocket message concurrently with the WebSocket connection closing when running on Apache Tomcat 8.5.0 to 8.5.75 or Apache…
PriorityP352high8.6CVSS 3.1
AVNACLPRNUINSUCHILAL
EPSS
8.03%
94.1th percentile
If a web application sends a WebSocket message concurrently with the WebSocket connection closing when running on Apache Tomcat 8.5.0 to 8.5.75 or Apache Tomcat 9.0.0.M1 to 9.0.20, it is possible that the application will continue to use the socket after it has been closed. The error handling triggered in this case could cause the a pooled object to be placed in the pool twice. This could result in subsequent connections using the same object concurrently which could result in data being returned to the wrong use and/or other errors.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | tomcat | — | — |
| apache | tomcat | >= 8.5.0 < 8.5.76 | 8.5.76 |
| apache | tomcat | >= 9.0.0 < 9.0.21 | 9.0.21 |
| apache_software_foundation | apache_tomcat | — | — |
| apache_software_foundation | apache_tomcat | — | — |
| debian | tomcat9 | < tomcat9 9.0.22-1 (bookworm) | tomcat9 9.0.22-1 (bookworm) |
| oracle | agile_plm | — | — |
CVSS provenance
nvdv3.18.6HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv8.6HIGH
vendor_apache8.6HIGH
vendor_debian8.6HIGH
vendor_oracle8.6HIGH
vendor_redhat8.6HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Oracle
Oracle Oracle Supply Chain Risk Matrix: Security (Apache Tomcat) — CVE-2022-25762
vendor_oracle·2022-07-15·CVSS 8.6
CVE-2022-25762 [HIGH] Oracle Oracle Supply Chain Risk Matrix: Security (Apache Tomcat) — CVE-2022-25762
Oracle Oracle Supply Chain Risk Matrix: Security (Apache Tomcat) vulnerability
CVE: CVE-2022-25762
CVSS: 8.6
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujul2022 (JUL 2022)
Red Hat
tomcat: request mixup
vendor_redhat·2022-05-12·CVSS 8.6
CVE-2022-25762 [HIGH] CWE-226 tomcat: request mixup
tomcat: request mixup
If a web application sends a WebSocket message concurrently with the WebSocket connection closing when running on Apache Tomcat 8.5.0 to 8.5.75 or Apache Tomcat 9.0.0.M1 to 9.0.20, it is possible that the application will continue to use the socket after it has been closed. The error handling triggered in this case could cause the a pooled object to be placed in the pool twice. This could result in subsequent connections using the same object concurrently which could result in data being returned to the wrong use and/or other errors.
A flaw was found in the tomcat package. When a web application sends a WebSocket message concurrently with the WebSocket connection closing, the application may continue to use the socket after it has been closed. In this case, the erro
Debian
CVE-2022-25762: tomcat9 - If a web application sends a WebSocket message concurrently with the WebSocket c...
vendor_debian·2022·CVSS 8.6
CVE-2022-25762 [HIGH] CVE-2022-25762: tomcat9 - If a web application sends a WebSocket message concurrently with the WebSocket c...
If a web application sends a WebSocket message concurrently with the WebSocket connection closing when running on Apache Tomcat 8.5.0 to 8.5.75 or Apache Tomcat 9.0.0.M1 to 9.0.20, it is possible that the application will continue to use the socket after it has been closed. The error handling triggered in this case could cause the a pooled object to be placed in the pool twice. This could result in subsequent connections using the same object concurrently which could result in data being returned to the wrong use and/or other errors.
Scope: local
bookworm: resolved (fixed in 9.0.22-1)
bullseye: resolved (fixed in 9.0.22-1)
forky: resolved (fixed in 9.0.22-1)
sid: resolved (fixed in 9.0.22-1)
trixie: resolved (fixed in 9.0.22-1)
Apache
Apache tomcat: CVE-2022-25762
vendor_apache·CVSS 8.6
CVE-2022-25762 [HIGH] Apache tomcat: CVE-2022-25762
Apache tomcat: CVE-2022-25762
If a web application sends a WebSocket message concurrently with the WebSocket connection closing, it is possible that the application will continue to use the socket after it has been closed. The error handling triggered in this case could cause the a pooled object to be placed in the pool twice. This could result in subsequent connections using the same object concurrently which could result in data being returned to the wrong use and/or other errors. This was fixed with commit 01f2cf25 . This issue was identified by the Apache Tomcat Security Team on 21 December 2021. The issue was made public on 12 May 2022. Affects: 8.5.0 to 8.5.75 20 January 2022 Fixed in Apache Tomcat 8.5.75 Note: The issue below was fixed in Apache Tomcat 8.5.74 but the release vote fo
OSV
Improper socket reuse in Apache Tomcat
osv·2022-05-14
CVE-2022-25762 [HIGH] Improper socket reuse in Apache Tomcat
Improper socket reuse in Apache Tomcat
If a web application sends a WebSocket message concurrently with the WebSocket connection closing when running on Apache Tomcat 8.5.0 to 8.5.75 or Apache Tomcat 9.0.0.M1 to 9.0.20, it is possible that the application will continue to use the socket after it has been closed. The error handling triggered in this case could cause the a pooled object to be placed in the pool twice. This could result in subsequent connections using the same object concurrently which could result in data being returned to the wrong use and/or other errors.
GHSA
Improper socket reuse in Apache Tomcat
ghsa·2022-05-14
CVE-2022-25762 [HIGH] CWE-404 Improper socket reuse in Apache Tomcat
Improper socket reuse in Apache Tomcat
If a web application sends a WebSocket message concurrently with the WebSocket connection closing when running on Apache Tomcat 8.5.0 to 8.5.75 or Apache Tomcat 9.0.0.M1 to 9.0.20, it is possible that the application will continue to use the socket after it has been closed. The error handling triggered in this case could cause the a pooled object to be placed in the pool twice. This could result in subsequent connections using the same object concurrently which could result in data being returned to the wrong use and/or other errors.
OSV
CVE-2022-25762: If a web application sends a WebSocket message concurrently with the WebSocket connection closing when running on Apache Tomcat 8
osv·2022-05-13·CVSS 8.6
CVE-2022-25762 [HIGH] CVE-2022-25762: If a web application sends a WebSocket message concurrently with the WebSocket connection closing when running on Apache Tomcat 8
If a web application sends a WebSocket message concurrently with the WebSocket connection closing when running on Apache Tomcat 8.5.0 to 8.5.75 or Apache Tomcat 9.0.0.M1 to 9.0.20, it is possible that the application will continue to use the socket after it has been closed. The error handling triggered in this case could cause the a pooled object to be placed in the pool twice. This could result in subsequent connections using the same object concurrently which could result in data being returned to the wrong use and/or other errors.
No detection rules found.
No public exploits indexed.
https://lists.apache.org/thread/6ckmjfb1k61dyzkto9vm2k5jvt4o7w7chttps://security.netapp.com/advisory/ntap-20220629-0003/https://www.oracle.com/security-alerts/cpujul2022.htmlhttps://lists.apache.org/thread/6ckmjfb1k61dyzkto9vm2k5jvt4o7w7chttps://security.netapp.com/advisory/ntap-20220629-0003/https://www.oracle.com/security-alerts/cpujul2022.html
2022-05-13
Published