PT-2022-2604 · Apache+4 · Apache Tomcat+4

4Ra1N

·

Published

2020-09-30

·

Updated

2026-05-18

·

CVE-2022-25762

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:N/C:C/I:P/A:P
Name of the Vulnerable Software and Affected Versions Apache Tomcat versions 8.5.0 through 8.5.75 Apache Tomcat versions 9.0.0.M1 through 9.0.20
Description The issue is related to errors when a web application sends a WebSocket message concurrently with the WebSocket connection closing. This could cause the application to continue using the socket after it has been closed, leading to a pooled object being placed in the pool twice. As a result, subsequent connections may use the same object concurrently, potentially causing data to be returned to the wrong user and/or other errors.
Recommendations For Apache Tomcat versions 8.5.0 through 8.5.75, update to a version outside of this range to resolve the issue. For Apache Tomcat versions 9.0.0.M1 through 9.0.20, update to a version outside of this range to resolve the issue. As a temporary workaround, consider disabling WebSocket functionality until a patch is available. Restrict access to sensitive data to minimize the risk of exploitation.

Exploit

Fix

Race Condition

Improper Resource Release

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2020-2892
ALT-PU-2020-3213
ALT-PU-2021-2858
BDU:2022-03062
BIT-TOMCAT-2022-25762
CESA-2020_4847
CVE-2022-25762
GHSA-H3CH-5PP2-VH6W
OESA-2024-2402
OESA-2024-2403
OESA-2024-2404
OESA-2024-2405
OESA-2024-2460
RHSA-2020:4847
RHSA-2020_4847
RLSA-2020:4847
ROSA-SA-2023-2258

Affected Products

Alt Linux
Apache Tomcat
Centos
Red Hat
Rocky Linux