BIT-tomcat-2021-43980

See a problem?
Import Source
https://github.com/bitnami/vulndb/tree/main/data/tomcat/BIT-tomcat-2021-43980.json
JSON Data
https://api.osv.dev/v1/vulns/BIT-tomcat-2021-43980
Aliases
Published
2024-03-06T11:09:43.693Z
Modified
2024-03-06T11:25:28.861Z
Summary
[none]
Details

The simplified implementation of blocking reads and writes introduced in Tomcat 10 and back-ported to Tomcat 9.0.47 onwards exposed a long standing (but extremely hard to trigger) concurrency bug in Apache Tomcat 10.1.0 to 10.1.0-M12, 10.0.0-M1 to 10.0.18, 9.0.0-M1 to 9.0.60 and 8.5.0 to 8.5.77 that could cause client connections to share an Http11Processor instance resulting in responses, or part responses, to be received by the wrong client.

References

Affected packages

Bitnami / tomcat

Package

Name
tomcat
Purl
pkg:bitnami/tomcat

Severity

  • 3.7 (Low) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N CVSS Calculator

Affected ranges

Type
SEMVER
Events
Introduced
8.5.0
Fixed
8.5.77
Introduced
9.0.0
Fixed
9.0.60
Introduced
10.0.0
Fixed
10.0.18
Type
SEMVER
Events
Introduced
10.1.0-milestone1
Last affected
10.1.0-milestone1
Introduced
10.1.0-milestone10
Last affected
10.1.0-milestone10
Introduced
10.1.0-milestone11
Last affected
10.1.0-milestone11
Introduced
10.1.0-milestone12
Last affected
10.1.0-milestone12
Introduced
10.1.0-milestone2
Last affected
10.1.0-milestone2
Introduced
10.1.0-milestone3
Last affected
10.1.0-milestone3
Introduced
10.1.0-milestone4
Last affected
10.1.0-milestone4
Introduced
10.1.0-milestone5
Last affected
10.1.0-milestone5
Introduced
10.1.0-milestone6
Last affected
10.1.0-milestone6
Introduced
10.1.0-milestone7
Last affected
10.1.0-milestone7
Introduced
10.1.0-milestone8
Last affected
10.1.0-milestone8
Introduced
10.1.0-milestone9
Last affected
10.1.0-milestone9