CVE Vulnerabilities

CVE-2020-13943

Published: Oct 12, 2020 | Modified: Nov 21, 2024
CVSS 3.x
4.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
CVSS 2.x
4 MEDIUM
AV:N/AC:L/Au:S/C:P/I:N/A:N
RedHat/V2
RedHat/V3
5.3 MODERATE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

If an HTTP/2 client connecting to Apache Tomcat 10.0.0-M1 to 10.0.0-M7, 9.0.0.M1 to 9.0.37 or 8.5.0 to 8.5.57 exceeded the agreed maximum number of concurrent streams for a connection (in violation of the HTTP/2 protocol), it was possible that a subsequent request made on that connection could contain HTTP headers - including HTTP/2 pseudo headers - from a previous request rather than the intended headers. This could lead to users seeing responses for unexpected resources.

Affected Software

NameVendorStart VersionEnd Version
TomcatApache8.5.0 (including)8.5.0 (including)
TomcatApache8.5.1 (including)8.5.1 (including)
TomcatApache8.5.2 (including)8.5.2 (including)
TomcatApache8.5.3 (including)8.5.3 (including)
TomcatApache8.5.4 (including)8.5.4 (including)
TomcatApache8.5.5 (including)8.5.5 (including)
TomcatApache8.5.6 (including)8.5.6 (including)
TomcatApache8.5.7 (including)8.5.7 (including)
TomcatApache8.5.8 (including)8.5.8 (including)
TomcatApache8.5.9 (including)8.5.9 (including)
TomcatApache8.5.10 (including)8.5.10 (including)
TomcatApache8.5.11 (including)8.5.11 (including)
TomcatApache8.5.12 (including)8.5.12 (including)
TomcatApache8.5.13 (including)8.5.13 (including)
TomcatApache8.5.14 (including)8.5.14 (including)
TomcatApache8.5.15 (including)8.5.15 (including)
TomcatApache8.5.16 (including)8.5.16 (including)
TomcatApache8.5.17 (including)8.5.17 (including)
TomcatApache8.5.18 (including)8.5.18 (including)
TomcatApache8.5.19 (including)8.5.19 (including)
TomcatApache8.5.20 (including)8.5.20 (including)
TomcatApache8.5.21 (including)8.5.21 (including)
TomcatApache8.5.22 (including)8.5.22 (including)
TomcatApache8.5.23 (including)8.5.23 (including)
TomcatApache8.5.24 (including)8.5.24 (including)
TomcatApache8.5.25 (including)8.5.25 (including)
TomcatApache8.5.26 (including)8.5.26 (including)
TomcatApache8.5.27 (including)8.5.27 (including)
TomcatApache8.5.28 (including)8.5.28 (including)
TomcatApache8.5.29 (including)8.5.29 (including)
TomcatApache8.5.30 (including)8.5.30 (including)
TomcatApache8.5.31 (including)8.5.31 (including)
TomcatApache8.5.32 (including)8.5.32 (including)
TomcatApache8.5.33 (including)8.5.33 (including)
TomcatApache8.5.34 (including)8.5.34 (including)
TomcatApache8.5.35 (including)8.5.35 (including)
TomcatApache8.5.36 (including)8.5.36 (including)
TomcatApache8.5.37 (including)8.5.37 (including)
TomcatApache8.5.38 (including)8.5.38 (including)
TomcatApache8.5.39 (including)8.5.39 (including)
TomcatApache8.5.40 (including)8.5.40 (including)
TomcatApache8.5.41 (including)8.5.41 (including)
TomcatApache8.5.42 (including)8.5.42 (including)
TomcatApache8.5.43 (including)8.5.43 (including)
TomcatApache8.5.44 (including)8.5.44 (including)
TomcatApache8.5.45 (including)8.5.45 (including)
TomcatApache8.5.46 (including)8.5.46 (including)
TomcatApache8.5.47 (including)8.5.47 (including)
TomcatApache8.5.48 (including)8.5.48 (including)
TomcatApache8.5.49 (including)8.5.49 (including)
TomcatApache8.5.50 (including)8.5.50 (including)
TomcatApache8.5.51 (including)8.5.51 (including)
TomcatApache8.5.52 (including)8.5.52 (including)
TomcatApache8.5.53 (including)8.5.53 (including)
TomcatApache8.5.54 (including)8.5.54 (including)
TomcatApache8.5.55 (including)8.5.55 (including)
TomcatApache8.5.56 (including)8.5.56 (including)
TomcatApache8.5.57 (including)8.5.57 (including)
TomcatApache9.0.0-milestone10 (including)9.0.0-milestone10 (including)
TomcatApache9.0.0-milestone11 (including)9.0.0-milestone11 (including)
TomcatApache9.0.0-milestone12 (including)9.0.0-milestone12 (including)
TomcatApache9.0.0-milestone13 (including)9.0.0-milestone13 (including)
TomcatApache9.0.0-milestone14 (including)9.0.0-milestone14 (including)
TomcatApache9.0.0-milestone15 (including)9.0.0-milestone15 (including)
TomcatApache9.0.0-milestone16 (including)9.0.0-milestone16 (including)
TomcatApache9.0.0-milestone17 (including)9.0.0-milestone17 (including)
TomcatApache9.0.0-milestone18 (including)9.0.0-milestone18 (including)
TomcatApache9.0.0-milestone19 (including)9.0.0-milestone19 (including)
TomcatApache9.0.0-milestone20 (including)9.0.0-milestone20 (including)
TomcatApache9.0.0-milestone21 (including)9.0.0-milestone21 (including)
TomcatApache9.0.0-milestone22 (including)9.0.0-milestone22 (including)
TomcatApache9.0.0-milestone23 (including)9.0.0-milestone23 (including)
TomcatApache9.0.0-milestone24 (including)9.0.0-milestone24 (including)
TomcatApache9.0.0-milestone25 (including)9.0.0-milestone25 (including)
TomcatApache9.0.0-milestone26 (including)9.0.0-milestone26 (including)
TomcatApache9.0.0-milestone27 (including)9.0.0-milestone27 (including)
TomcatApache9.0.0-milestone5 (including)9.0.0-milestone5 (including)
TomcatApache9.0.0-milestone6 (including)9.0.0-milestone6 (including)
TomcatApache9.0.0-milestone7 (including)9.0.0-milestone7 (including)
TomcatApache9.0.0-milestone8 (including)9.0.0-milestone8 (including)
TomcatApache9.0.0-milestone9 (including)9.0.0-milestone9 (including)
TomcatApache9.0.1 (including)9.0.1 (including)
TomcatApache9.0.2 (including)9.0.2 (including)
TomcatApache9.0.3 (including)9.0.3 (including)
TomcatApache9.0.4 (including)9.0.4 (including)
TomcatApache9.0.5 (including)9.0.5 (including)
TomcatApache9.0.6 (including)9.0.6 (including)
TomcatApache9.0.7 (including)9.0.7 (including)
TomcatApache9.0.8 (including)9.0.8 (including)
TomcatApache9.0.9 (including)9.0.9 (including)
TomcatApache9.0.10 (including)9.0.10 (including)
TomcatApache9.0.11 (including)9.0.11 (including)
TomcatApache9.0.12 (including)9.0.12 (including)
TomcatApache9.0.13 (including)9.0.13 (including)
TomcatApache9.0.14 (including)9.0.14 (including)
TomcatApache9.0.15 (including)9.0.15 (including)
TomcatApache9.0.16 (including)9.0.16 (including)
TomcatApache9.0.17 (including)9.0.17 (including)
TomcatApache9.0.18 (including)9.0.18 (including)
TomcatApache9.0.19 (including)9.0.19 (including)
TomcatApache9.0.20 (including)9.0.20 (including)
TomcatApache9.0.21 (including)9.0.21 (including)
TomcatApache9.0.22 (including)9.0.22 (including)
TomcatApache9.0.23 (including)9.0.23 (including)
TomcatApache9.0.24 (including)9.0.24 (including)
TomcatApache9.0.25 (including)9.0.25 (including)
TomcatApache9.0.26 (including)9.0.26 (including)
TomcatApache9.0.27 (including)9.0.27 (including)
TomcatApache9.0.28 (including)9.0.28 (including)
TomcatApache9.0.29 (including)9.0.29 (including)
TomcatApache9.0.30 (including)9.0.30 (including)
TomcatApache9.0.31 (including)9.0.31 (including)
TomcatApache9.0.32 (including)9.0.32 (including)
TomcatApache9.0.33 (including)9.0.33 (including)
TomcatApache9.0.34 (including)9.0.34 (including)
TomcatApache9.0.35 (including)9.0.35 (including)
TomcatApache9.0.36 (including)9.0.36 (including)
TomcatApache9.0.37 (including)9.0.37 (including)
TomcatApache10.0.0-milestone1 (including)10.0.0-milestone1 (including)
TomcatApache10.0.0-milestone2 (including)10.0.0-milestone2 (including)
TomcatApache10.0.0-milestone3 (including)10.0.0-milestone3 (including)
TomcatApache10.0.0-milestone4 (including)10.0.0-milestone4 (including)
TomcatApache10.0.0-milestone5 (including)10.0.0-milestone5 (including)
TomcatApache10.0.0-milestone6 (including)10.0.0-milestone6 (including)
TomcatApache10.0.0-milestone7 (including)10.0.0-milestone7 (including)
Red Hat Fuse 7.10RedHattomcat*
Red Hat JBoss Web Server 5RedHattomcat*
Red Hat JBoss Web Server 5.4 on RHEL 7RedHatjws5-tomcat-0:9.0.36-9.redhat_8.1.el7jws*
Red Hat JBoss Web Server 5.4 on RHEL 7RedHatjws5-tomcat-native-0:1.2.25-3.redhat_3.el7jws*
Red Hat JBoss Web Server 5.4 on RHEL 8RedHatjws5-tomcat-0:9.0.36-9.redhat_8.1.el8jws*
Red Hat JBoss Web Server 5.4 on RHEL 8RedHatjws5-tomcat-native-0:1.2.25-3.redhat_3.el8jws*
Red Hat Support for Spring Boot 2.4.9RedHattomcat*
Tomcat8Ubuntutrusty*
Tomcat9Ubuntutrusty*
Tomcat9Ubuntuupstream*

References