PT-2020-13794 · Apache+4 · Apache Tomcat+4

Published

2020-09-15

·

Updated

2026-03-26

·

CVE-2020-13943

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Apache Tomcat versions 8.5.0 through 8.5.57 Apache Tomcat versions 9.0.0.M1 through 9.0.37 Apache Tomcat versions 10.0.0-M1 through 10.0.0-M7
Description If an HTTP/2 client exceeds the agreed maximum number of concurrent streams for a connection, in violation of the HTTP/2 protocol, it is possible that a subsequent request made on that connection could contain HTTP headers, including HTTP/2 pseudo headers, from a previous request rather than the intended headers. This could lead to users seeing responses for unexpected resources.
Recommendations For Apache Tomcat versions 8.5.0 through 8.5.57, update to a version outside of this range to resolve the issue. For Apache Tomcat versions 9.0.0.M1 through 9.0.37, update to a version outside of this range to resolve the issue. For Apache Tomcat versions 10.0.0-M1 through 10.0.0-M7, update to a version outside of this range to resolve the issue. As a temporary workaround, consider restricting the maximum number of concurrent streams for a connection to prevent violation of the HTTP/2 protocol.

Exploit

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2021-1921
ALT-PU-2025-9146
BIT-TOMCAT-2020-13943
CVE-2020-13943
DLA-2407-1
DSA-4835-1
GHSA-F268-65QC-98VG
MGASA-2020-0397
OPENSUSE-SU-2020:1799-1
OPENSUSE-SU-2020:1842-1
OPENSUSE-SU-2020_1799-1
OPENSUSE-SU-2020_1842-1
OPENSUSE-SU-2024:11468-1
OPENSUSE-SU-2024:13441-1
RHSA-2021:0494
ROSA-SA-2024-2544
SUSE-SU-2020:2996-1
SUSE-SU-2020:3068-1
SUSE-SU-2020:3069-1
SUSE-SU-2020_2996-1
SUSE-SU-2020_3068-1
SUSE-SU-2020_3069-1
SUSE-SU-2021:0040-1
SUSE-SU-2021_0040-1
SUSE-SU-2026:1058-1
USN-5360-1

Affected Products

Alt Linux
Apache Tomcat
Linuxmint
Suse
Ubuntu