CVE-2020-17527

🟡 Monitoruj

Luka w Apache Tomcat pozwala na potencjalne wyciek informacji między żądaniami HTTP/2.

CVSS
7.5
EPSS
24.6%
Exploit
none
Vendor
apache
Opis źródłowy (NVD)

While investigating bug 64830 it was discovered that Apache Tomcat 10.0.0-M1 to 10.0.0-M9, 9.0.0-M1 to 9.0.39 and 8.5.0 to 8.5.59 could re-use an HTTP request header value from the previous stream received on an HTTP/2 connection for the request associated with the subsequent stream. While this would most likely lead to an error and the closure of the HTTP/2 connection, it is possible that information could leak between requests.

brak Brak patcha
Źródła i daty
ŹródłoWartość
NVD – CVSS7.5
CISA KEV (aktywnie wykorzystywane)Nie
FIRST EPSS (prawdopodobieństwo exploita)24.6%
Opublikowano (NVD)2020-12-03 19:15:12 UTC
Ostatnia modyfikacja (NVD)2026-10-08 22:16:57 UTC
Referencje