BIT-tomcat-2020-13943

See a problem?
Import Source
https://github.com/bitnami/vulndb/tree/main/data/tomcat/BIT-tomcat-2020-13943.json
JSON Data
https://api.test.osv.dev/v1/vulns/BIT-tomcat-2020-13943
Aliases
Published
2024-03-06T11:11:40.396Z
Modified
2025-11-06T13:25:46.476Z
Summary
[none]
Details

If an HTTP/2 client connecting to Apache Tomcat 10.0.0-M1 to 10.0.0-M7, 9.0.0.M1 to 9.0.37 or 8.5.0 to 8.5.57 exceeded the agreed maximum number of concurrent streams for a connection (in violation of the HTTP/2 protocol), it was possible that a subsequent request made on that connection could contain HTTP headers - including HTTP/2 pseudo headers - from a previous request rather than the intended headers. This could lead to users seeing responses for unexpected resources.

Database specific
{
    "cpes": [
        "cpe:2.3:a:apache:tomcat:10.0.0:milestone1:*:*:*:*:*:*",
        "cpe:2.3:a:apache:tomcat:10.0.0:milestone2:*:*:*:*:*:*",
        "cpe:2.3:a:apache:tomcat:10.0.0:milestone3:*:*:*:*:*:*",
        "cpe:2.3:a:apache:tomcat:10.0.0:milestone4:*:*:*:*:*:*",
        "cpe:2.3:a:apache:tomcat:10.0.0:milestone5:*:*:*:*:*:*",
        "cpe:2.3:a:apache:tomcat:10.0.0:milestone6:*:*:*:*:*:*",
        "cpe:2.3:a:apache:tomcat:10.0.0:milestone7:*:*:*:*:*:*",
        "cpe:2.3:a:apache:tomcat:8.5.0:*:*:*:*:*:*:*",
        "cpe:2.3:a:apache:tomcat:8.5.10:*:*:*:*:*:*:*",
        "cpe:2.3:a:apache:tomcat:8.5.11:*:*:*:*:*:*:*",
        "cpe:2.3:a:apache:tomcat:8.5.12:*:*:*:*:*:*:*",
        "cpe:2.3:a:apache:tomcat:8.5.13:*:*:*:*:*:*:*",
        "cpe:2.3:a:apache:tomcat:8.5.14:*:*:*:*:*:*:*",
        "cpe:2.3:a:apache:tomcat:8.5.15:*:*:*:*:*:*:*",
        "cpe:2.3:a:apache:tomcat:8.5.16:*:*:*:*:*:*:*",
        "cpe:2.3:a:apache:tomcat:8.5.17:*:*:*:*:*:*:*",
        "cpe:2.3:a:apache:tomcat:8.5.18:*:*:*:*:*:*:*",
        "cpe:2.3:a:apache:tomcat:8.5.19:*:*:*:*:*:*:*",
        "cpe:2.3:a:apache:tomcat:8.5.1:*:*:*:*:*:*:*",
        "cpe:2.3:a:apache:tomcat:8.5.20:*:*:*:*:*:*:*",
        "cpe:2.3:a:apache:tomcat:8.5.21:*:*:*:*:*:*:*",
        "cpe:2.3:a:apache:tomcat:8.5.22:*:*:*:*:*:*:*",
        "cpe:2.3:a:apache:tomcat:8.5.23:*:*:*:*:*:*:*",
        "cpe:2.3:a:apache:tomcat:8.5.24:*:*:*:*:*:*:*",
        "cpe:2.3:a:apache:tomcat:8.5.25:*:*:*:*:*:*:*",
        "cpe:2.3:a:apache:tomcat:8.5.26:*:*:*:*:*:*:*",
        "cpe:2.3:a:apache:tomcat:8.5.27:*:*:*:*:*:*:*",
        "cpe:2.3:a:apache:tomcat:8.5.28:*:*:*:*:*:*:*",
        "cpe:2.3:a:apache:tomcat:8.5.29:*:*:*:*:*:*:*",
        "cpe:2.3:a:apache:tomcat:8.5.2:*:*:*:*:*:*:*",
        "cpe:2.3:a:apache:tomcat:8.5.30:*:*:*:*:*:*:*",
        "cpe:2.3:a:apache:tomcat:8.5.31:*:*:*:*:*:*:*",
        "cpe:2.3:a:apache:tomcat:8.5.32:*:*:*:*:*:*:*",
        "cpe:2.3:a:apache:tomcat:8.5.33:*:*:*:*:*:*:*",
        "cpe:2.3:a:apache:tomcat:8.5.34:*:*:*:*:*:*:*",
        "cpe:2.3:a:apache:tomcat:8.5.35:*:*:*:*:*:*:*",
        "cpe:2.3:a:apache:tomcat:8.5.36:*:*:*:*:*:*:*",
        "cpe:2.3:a:apache:tomcat:8.5.37:*:*:*:*:*:*:*",
        "cpe:2.3:a:apache:tomcat:8.5.38:*:*:*:*:*:*:*",
        "cpe:2.3:a:apache:tomcat:8.5.39:*:*:*:*:*:*:*",
        "cpe:2.3:a:apache:tomcat:8.5.3:*:*:*:*:*:*:*",
        "cpe:2.3:a:apache:tomcat:8.5.40:*:*:*:*:*:*:*",
        "cpe:2.3:a:apache:tomcat:8.5.41:*:*:*:*:*:*:*",
        "cpe:2.3:a:apache:tomcat:8.5.42:*:*:*:*:*:*:*",
        "cpe:2.3:a:apache:tomcat:8.5.43:*:*:*:*:*:*:*",
        "cpe:2.3:a:apache:tomcat:8.5.44:*:*:*:*:*:*:*",
        "cpe:2.3:a:apache:tomcat:8.5.45:*:*:*:*:*:*:*",
        "cpe:2.3:a:apache:tomcat:8.5.46:*:*:*:*:*:*:*",
        "cpe:2.3:a:apache:tomcat:8.5.47:*:*:*:*:*:*:*",
        "cpe:2.3:a:apache:tomcat:8.5.48:*:*:*:*:*:*:*",
        "cpe:2.3:a:apache:tomcat:8.5.49:*:*:*:*:*:*:*",
        "cpe:2.3:a:apache:tomcat:8.5.4:*:*:*:*:*:*:*",
        "cpe:2.3:a:apache:tomcat:8.5.50:*:*:*:*:*:*:*",
        "cpe:2.3:a:apache:tomcat:8.5.51:*:*:*:*:*:*:*",
        "cpe:2.3:a:apache:tomcat:8.5.52:*:*:*:*:*:*:*",
        "cpe:2.3:a:apache:tomcat:8.5.53:*:*:*:*:*:*:*",
        "cpe:2.3:a:apache:tomcat:8.5.54:*:*:*:*:*:*:*",
        "cpe:2.3:a:apache:tomcat:8.5.55:*:*:*:*:*:*:*",
        "cpe:2.3:a:apache:tomcat:8.5.56:*:*:*:*:*:*:*",
        "cpe:2.3:a:apache:tomcat:8.5.57:*:*:*:*:*:*:*",
        "cpe:2.3:a:apache:tomcat:8.5.5:*:*:*:*:*:*:*",
        "cpe:2.3:a:apache:tomcat:8.5.6:*:*:*:*:*:*:*",
        "cpe:2.3:a:apache:tomcat:8.5.7:*:*:*:*:*:*:*",
        "cpe:2.3:a:apache:tomcat:8.5.8:*:*:*:*:*:*:*",
        "cpe:2.3:a:apache:tomcat:8.5.9:*:*:*:*:*:*:*",
        "cpe:2.3:a:apache:tomcat:9.0.0:milestone10:*:*:*:*:*:*",
        "cpe:2.3:a:apache:tomcat:9.0.0:milestone11:*:*:*:*:*:*",
        "cpe:2.3:a:apache:tomcat:9.0.0:milestone12:*:*:*:*:*:*",
        "cpe:2.3:a:apache:tomcat:9.0.0:milestone13:*:*:*:*:*:*",
        "cpe:2.3:a:apache:tomcat:9.0.0:milestone14:*:*:*:*:*:*",
        "cpe:2.3:a:apache:tomcat:9.0.0:milestone15:*:*:*:*:*:*",
        "cpe:2.3:a:apache:tomcat:9.0.0:milestone16:*:*:*:*:*:*",
        "cpe:2.3:a:apache:tomcat:9.0.0:milestone17:*:*:*:*:*:*",
        "cpe:2.3:a:apache:tomcat:9.0.0:milestone18:*:*:*:*:*:*",
        "cpe:2.3:a:apache:tomcat:9.0.0:milestone19:*:*:*:*:*:*",
        "cpe:2.3:a:apache:tomcat:9.0.0:milestone20:*:*:*:*:*:*",
        "cpe:2.3:a:apache:tomcat:9.0.0:milestone21:*:*:*:*:*:*",
        "cpe:2.3:a:apache:tomcat:9.0.0:milestone22:*:*:*:*:*:*",
        "cpe:2.3:a:apache:tomcat:9.0.0:milestone23:*:*:*:*:*:*",
        "cpe:2.3:a:apache:tomcat:9.0.0:milestone24:*:*:*:*:*:*",
        "cpe:2.3:a:apache:tomcat:9.0.0:milestone25:*:*:*:*:*:*",
        "cpe:2.3:a:apache:tomcat:9.0.0:milestone26:*:*:*:*:*:*",
        "cpe:2.3:a:apache:tomcat:9.0.0:milestone27:*:*:*:*:*:*",
        "cpe:2.3:a:apache:tomcat:9.0.0:milestone5:*:*:*:*:*:*",
        "cpe:2.3:a:apache:tomcat:9.0.0:milestone6:*:*:*:*:*:*",
        "cpe:2.3:a:apache:tomcat:9.0.0:milestone7:*:*:*:*:*:*",
        "cpe:2.3:a:apache:tomcat:9.0.0:milestone8:*:*:*:*:*:*",
        "cpe:2.3:a:apache:tomcat:9.0.0:milestone9:*:*:*:*:*:*",
        "cpe:2.3:a:apache:tomcat:9.0.10:*:*:*:*:*:*:*",
        "cpe:2.3:a:apache:tomcat:9.0.11:*:*:*:*:*:*:*",
        "cpe:2.3:a:apache:tomcat:9.0.12:*:*:*:*:*:*:*",
        "cpe:2.3:a:apache:tomcat:9.0.13:*:*:*:*:*:*:*",
        "cpe:2.3:a:apache:tomcat:9.0.14:*:*:*:*:*:*:*",
        "cpe:2.3:a:apache:tomcat:9.0.15:*:*:*:*:*:*:*",
        "cpe:2.3:a:apache:tomcat:9.0.16:*:*:*:*:*:*:*",
        "cpe:2.3:a:apache:tomcat:9.0.17:*:*:*:*:*:*:*",
        "cpe:2.3:a:apache:tomcat:9.0.18:*:*:*:*:*:*:*",
        "cpe:2.3:a:apache:tomcat:9.0.19:*:*:*:*:*:*:*",
        "cpe:2.3:a:apache:tomcat:9.0.1:*:*:*:*:*:*:*",
        "cpe:2.3:a:apache:tomcat:9.0.20:*:*:*:*:*:*:*",
        "cpe:2.3:a:apache:tomcat:9.0.21:*:*:*:*:*:*:*",
        "cpe:2.3:a:apache:tomcat:9.0.22:*:*:*:*:*:*:*",
        "cpe:2.3:a:apache:tomcat:9.0.23:*:*:*:*:*:*:*",
        "cpe:2.3:a:apache:tomcat:9.0.24:*:*:*:*:*:*:*",
        "cpe:2.3:a:apache:tomcat:9.0.25:*:*:*:*:*:*:*",
        "cpe:2.3:a:apache:tomcat:9.0.26:*:*:*:*:*:*:*",
        "cpe:2.3:a:apache:tomcat:9.0.27:*:*:*:*:*:*:*",
        "cpe:2.3:a:apache:tomcat:9.0.28:*:*:*:*:*:*:*",
        "cpe:2.3:a:apache:tomcat:9.0.29:*:*:*:*:*:*:*",
        "cpe:2.3:a:apache:tomcat:9.0.2:*:*:*:*:*:*:*",
        "cpe:2.3:a:apache:tomcat:9.0.30:*:*:*:*:*:*:*",
        "cpe:2.3:a:apache:tomcat:9.0.31:*:*:*:*:*:*:*",
        "cpe:2.3:a:apache:tomcat:9.0.32:*:*:*:*:*:*:*",
        "cpe:2.3:a:apache:tomcat:9.0.33:*:*:*:*:*:*:*",
        "cpe:2.3:a:apache:tomcat:9.0.34:*:*:*:*:*:*:*",
        "cpe:2.3:a:apache:tomcat:9.0.35:*:*:*:*:*:*:*",
        "cpe:2.3:a:apache:tomcat:9.0.36:*:*:*:*:*:*:*",
        "cpe:2.3:a:apache:tomcat:9.0.37:*:*:*:*:*:*:*",
        "cpe:2.3:a:apache:tomcat:9.0.3:*:*:*:*:*:*:*",
        "cpe:2.3:a:apache:tomcat:9.0.4:*:*:*:*:*:*:*",
        "cpe:2.3:a:apache:tomcat:9.0.5:*:*:*:*:*:*:*",
        "cpe:2.3:a:apache:tomcat:9.0.6:*:*:*:*:*:*:*",
        "cpe:2.3:a:apache:tomcat:9.0.7:*:*:*:*:*:*:*",
        "cpe:2.3:a:apache:tomcat:9.0.8:*:*:*:*:*:*:*",
        "cpe:2.3:a:apache:tomcat:9.0.9:*:*:*:*:*:*:*",
        "cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:*"
    ],
    "severity": "Medium"
}
References

Affected packages

Bitnami / tomcat

Package

Name
tomcat
Purl
pkg:bitnami/tomcat

Severity

  • 4.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N CVSS Calculator

Affected ranges

Type
SEMVER
Events
Introduced
8.5.0
Fixed
8.5.1
Introduced
8.5.1
Fixed
8.5.2
Introduced
8.5.2
Fixed
8.5.3
Introduced
8.5.3
Fixed
8.5.4
Introduced
8.5.4
Fixed
8.5.5
Introduced
8.5.5
Fixed
8.5.6
Introduced
8.5.6
Fixed
8.5.7
Introduced
8.5.7
Fixed
8.5.8
Introduced
8.5.8
Fixed
8.5.9
Introduced
8.5.9
Fixed
8.5.10
Introduced
8.5.10
Fixed
8.5.11
Introduced
8.5.11
Fixed
8.5.12
Introduced
8.5.12
Fixed
8.5.13
Introduced
8.5.13
Fixed
8.5.14
Introduced
8.5.14
Fixed
8.5.15
Introduced
8.5.15
Fixed
8.5.16
Introduced
8.5.16
Fixed
8.5.17
Introduced
8.5.17
Fixed
8.5.18
Introduced
8.5.18
Fixed
8.5.19
Introduced
8.5.19
Fixed
8.5.20
Introduced
8.5.20
Fixed
8.5.21
Introduced
8.5.21
Fixed
8.5.22
Introduced
8.5.22
Fixed
8.5.23
Introduced
8.5.23
Fixed
8.5.24
Introduced
8.5.24
Fixed
8.5.25
Introduced
8.5.25
Fixed
8.5.26
Introduced
8.5.26
Fixed
8.5.27
Introduced
8.5.27
Fixed
8.5.28
Introduced
8.5.28
Fixed
8.5.29
Introduced
8.5.29
Fixed
8.5.30
Introduced
8.5.30
Fixed
8.5.31
Introduced
8.5.31
Fixed
8.5.32
Introduced
8.5.32
Fixed
8.5.33
Introduced
8.5.33
Fixed
8.5.34
Introduced
8.5.34
Fixed
8.5.35
Introduced
8.5.35
Fixed
8.5.36
Introduced
8.5.36
Fixed
8.5.37
Introduced
8.5.37
Fixed
8.5.38
Introduced
8.5.38
Fixed
8.5.39
Introduced
8.5.39
Fixed
8.5.40
Introduced
8.5.40
Fixed
8.5.41
Introduced
8.5.41
Fixed
8.5.42
Introduced
8.5.42
Fixed
8.5.43
Introduced
8.5.43
Fixed
8.5.44
Introduced
8.5.44
Fixed
8.5.45
Introduced
8.5.45
Fixed
8.5.46
Introduced
8.5.46
Fixed
8.5.47
Introduced
8.5.47
Fixed
8.5.48
Introduced
8.5.48
Fixed
8.5.49
Introduced
8.5.49
Fixed
8.5.50
Introduced
8.5.50
Fixed
8.5.51
Introduced
8.5.51
Fixed
8.5.52
Introduced
8.5.52
Fixed
8.5.53
Introduced
8.5.53
Fixed
8.5.54
Introduced
8.5.54
Fixed
8.5.55
Introduced
8.5.55
Fixed
8.5.56
Introduced
8.5.56
Fixed
8.5.57
Introduced
8.5.57
Fixed
8.5.58
Introduced
9.0.0
Fixed
9.0.38