PT-2021-2443 · Apache+5 · Apache Tomcat+5

Published

2021-02-02

·

Updated

2026-03-26

·

CVE-2021-25122

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions: Apache Tomcat versions 8.5.0 through 8.5.61 Apache Tomcat versions 9.0.0.M1 through 9.0.41 Apache Tomcat versions 10.0.0-M1 through 10.0.0
Description: The issue is related to the implementation of the HTTP/2 protocol in Apache Tomcat, which could lead to a lack of protection for service data. When responding to new h2c connection requests, Apache Tomcat could duplicate request headers and a limited amount of request body from one request to another. This means that user A and user B could both see the results of user A's request, potentially affecting the confidentiality, integrity, and availability of protected information.
Recommendations: For Apache Tomcat versions 8.5.0 through 8.5.61, update to a version that includes the fix for this issue. For Apache Tomcat versions 9.0.0.M1 through 9.0.41, update to a version that includes the fix for this issue. For Apache Tomcat versions 10.0.0-M1 through 10.0.0, update to a version that includes the fix for this issue. As a temporary workaround, consider restricting access to sensitive data and limiting the amount of request body data that is processed by the server.

Exploit

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2021-1993
ALT-PU-2025-9146
BDU:2021-01807
BIT-TOMCAT-2021-25122
CVE-2021-25122
DLA-2594-1
DSA-4891-1
GHSA-J39C-C8HJ-X4J3
MGASA-2021-0357
OESA-2021-1117
OPENSUSE-SU-2021:0496-1
OPENSUSE-SU-2021_0496-1
OPENSUSE-SU-2024:11468-1
OPENSUSE-SU-2024:13441-1
RHSA-2021:2561
ROSA-SA-2023-2258
SUSE-SU-2021:0988-1
SUSE-SU-2021:0989-1
SUSE-SU-2021:1008-1
SUSE-SU-2021:1009-1
SUSE-SU-2026:1058-1
USN-5360-1
USN-6943-1

Affected Products

Alt Linux
Apache Tomcat
Astra Linux
Linuxmint
Suse
Ubuntu