PT-2021-2443 · Apache+5 · Apache Tomcat+5
Published
2021-02-02
·
Updated
2026-03-26
·
CVE-2021-25122
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
Apache Tomcat versions 8.5.0 through 8.5.61
Apache Tomcat versions 9.0.0.M1 through 9.0.41
Apache Tomcat versions 10.0.0-M1 through 10.0.0
Description:
The issue is related to the implementation of the HTTP/2 protocol in Apache Tomcat, which could lead to a lack of protection for service data. When responding to new h2c connection requests, Apache Tomcat could duplicate request headers and a limited amount of request body from one request to another. This means that user A and user B could both see the results of user A's request, potentially affecting the confidentiality, integrity, and availability of protected information.
Recommendations:
For Apache Tomcat versions 8.5.0 through 8.5.61, update to a version that includes the fix for this issue.
For Apache Tomcat versions 9.0.0.M1 through 9.0.41, update to a version that includes the fix for this issue.
For Apache Tomcat versions 10.0.0-M1 through 10.0.0, update to a version that includes the fix for this issue.
As a temporary workaround, consider restricting access to sensitive data and limiting the amount of request body data that is processed by the server.
Exploit
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Apache Tomcat
Astra Linux
Linuxmint
Suse
Ubuntu