CVE-2020-17527

Aliases:GHSA-vvw4-rfwf-p6hxBIT-tomcat-2020-17527
Modified
Published: 03 Dec 2020, 18:30
Last modified:13 Feb 2025, 16:27

Vulnerability Summary

Overall Risk (default)
medium
32/100
CVSS Score
7.5 HIGH
v3.1 (nvd)
EPSS Score
10.51% MEDIUM
11% probability 0.00%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

03 Dec 2020, 18:30
Published
Vulnerability first disclosed
13 Feb 2025, 16:27
Last Modified
Vulnerability information updated

Description

While investigating bug 64830 it was discovered that Apache Tomcat 10.0.0-M1 to 10.0.0-M9, 9.0.0-M1 to 9.0.39 and 8.5.0 to 8.5.59 could re-use an HTTP request header value from the previous stream received on an HTTP/2 connection for the request associated with the subsequent stream. While this would most likely lead to an error and the closure of the HTTP/2 connection, it is possible that information could leak between requests.

CVSS Metrics

  • v3.1HIGHScore: 7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
  • v2.0MEDIUMScore: 5AV:N/AC:L/Au:N/C:P/I:N/A:N

EPSS Trends

Current EPSS score: 10.51% Percentile: 93%

Techniques & Countermeasures

  • CWE-200Exposure of Sensitive Information to an Unauthorized Actor

    The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

Affected Systems

  • apache software foundationapache tomcat

    Apache Tomcat 10 10.0.0-M1 to 10.0.0-M9 | Apache Tomcat 9 9.0.0-M1 to 9.0.39 | Apache Tomcat 8.5 8.5.0 to 8.5.59

  • UnknownTomcat

    ≥ 8.5.1, ≤ 8.5.59 | ≥ 9.0.1, ≤ 9.0.35 | 9.0.0:milestone10 | 9.0.0:milestone11 | 9.0.0:milestone12 | 9.0.0:milestone13 | 9.0.0:milestone14 | 9.0.0:milestone15 | 9.0.0:milestone16 | 9.0.0:milestone17 | 9.0.0:milestone18 | 9.0.0:milestone19 | 9.0.0:milestone20 | 9.0.0:milestone21 | 9.0.0:milestone22 | 9.0.0:milestone23 | 9.0.0:milestone24 | 9.0.0:milestone25 | 9.0.0:milestone26 | 9.0.0:milestone27 | 9.0.0:milestone5 | 9.0.0:milestone6 | 9.0.0:milestone7 | 9.0.0:milestone8 | 9.0.0:milestone9 | 9.0.35-3.39.1 | 9.0.35-3.57.3 | 9.0.36 | 9.0.37 | 9.0.38 | 9.0.39 | 10.0.0:milestone1 | 10.0.0:milestone2 | 10.0.0:milestone3 | 10.0.0:milestone4 | 10.0.0:milestone5 | 10.0.0:milestone6 | 10.0.0:milestone7 | 10.0.0:milestone8 | 10.0.0:milestone9

  • debiandebian_linux

    9.0 | 10.0

  • org.apache.tomcattomcat-coyote

    ≥ 10.0.0-M1, < 10.0.0-M10 | ≥ 9.0.0-M1, < 9.0.40 | ≥ 8.5.0, < 8.5.60

  • netappelement_plug-in

    na

  • netapponcommand_system_manager

    ≥ 3.0.0, ≤ 3.1.3

  • oracleblockchain_platform

    < 21.1.2

  • oraclecommunications_cloud_native_core_binding_support_function

    1.10.0

  • oraclecommunications_cloud_native_core_policy

    1.14.0

  • oraclecommunications_instant_messaging_server

    10.0.1.5.0

  • oracleinstantis_enterprisetrack

    17.1 | 17.2 | 17.3

  • oraclemysql_enterprise_monitor

    < 8.0.23

  • oraclesd-wan_edge

    9.0

  • oracleworkload_manager

    18c | 19c

References (49)