
Cloud Vulnerability DB
A community-led vulnerabilities database
Apache Tomcat versions 10.0.0-M1 to 10.0.0-M9, 9.0.0-M1 to 9.0.39 and 8.5.0 to 8.5.59 could re-use an HTTP request header value from the previous stream received on an HTTP/2 connection for the request associated with the subsequent stream. The vulnerability was discovered while investigating bug 64830 and was disclosed on December 3, 2020 (Apache Security).
The vulnerability has a CVSS base score of 7.5 (HIGH) with vector (AV:N/AC:L/Au:N/C:H/I:N/A:N). It affects the HTTP/2 protocol implementation in Apache Tomcat, where header values from previous streams could be incorrectly reused in subsequent streams on the same HTTP/2 connection (Rapid7 DB).
While this vulnerability would most likely lead to an error and the closure of the HTTP/2 connection, it could potentially allow information to leak between different requests, potentially exposing sensitive data between different users or sessions (CVE Mitre).
The vulnerability is remotely exploitable without authentication, meaning an attacker can exploit it over a network without requiring user credentials. The attack complexity is considered low, requiring no special conditions for exploitation (NVD NIST).
Users should upgrade to Apache Tomcat versions 10.0.0-M10 or later, 9.0.40 or later, or 8.5.60 or later. If immediate upgrading is not possible, disabling HTTP/2 support can serve as a temporary workaround (Gentoo Security).
Multiple organizations and vendors responded to this vulnerability by releasing security advisories and patches, including Red Hat, Oracle, NetApp, and Debian. The vulnerability was rated as moderate severity by the Apache Tomcat Security Team (NetApp Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."