CVE-2020-13943

If an HTTP/2 client connecting to Apache Tomcat 10.0.0-M1 to 10.0.0-M7, 9.0.0.M1 to 9.0.37 or 8.5.0 to 8.5.57 exceeded the agreed maximum number of concurrent streams for a connection (in violation of the HTTP/2 protocol), it was possible that a subsequent request made on that connection could contain HTTP headers - including HTTP/2 pseudo headers - from a previous request rather than the intended headers. This could lead to users seeing responses for unexpected resources.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
4.3 MEDIUM
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
apacheCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 93%
VendorProductVersion
apachetomcat
8.5.0
apachetomcat
8.5.1
apachetomcat
8.5.2
apachetomcat
8.5.3
apachetomcat
8.5.4
apachetomcat
8.5.5
apachetomcat
8.5.6
apachetomcat
8.5.7
apachetomcat
8.5.8
apachetomcat
8.5.9
apachetomcat
8.5.10
apachetomcat
8.5.11
apachetomcat
8.5.12
apachetomcat
8.5.13
apachetomcat
8.5.14
apachetomcat
8.5.15
apachetomcat
8.5.16
apachetomcat
8.5.17
apachetomcat
8.5.18
apachetomcat
8.5.19
apachetomcat
8.5.20
apachetomcat
8.5.21
apachetomcat
8.5.22
apachetomcat
8.5.23
apachetomcat
8.5.24
apachetomcat
8.5.25
apachetomcat
8.5.26
apachetomcat
8.5.27
apachetomcat
8.5.28
apachetomcat
8.5.29
apachetomcat
8.5.30
apachetomcat
8.5.31
apachetomcat
8.5.32
apachetomcat
8.5.33
apachetomcat
8.5.34
apachetomcat
8.5.35
apachetomcat
8.5.36
apachetomcat
8.5.37
apachetomcat
8.5.38
apachetomcat
8.5.39
apachetomcat
8.5.40
apachetomcat
8.5.41
apachetomcat
8.5.42
apachetomcat
8.5.43
apachetomcat
8.5.44
apachetomcat
8.5.45
apachetomcat
8.5.46
apachetomcat
8.5.47
apachetomcat
8.5.48
apachetomcat
8.5.49
apachetomcat
8.5.50
apachetomcat
8.5.51
apachetomcat
8.5.52
apachetomcat
8.5.53
apachetomcat
8.5.54
apachetomcat
8.5.55
apachetomcat
8.5.56
apachetomcat
8.5.57
apachetomcat
9.0.0:milestone10
apachetomcat
9.0.0:milestone11
apachetomcat
9.0.0:milestone12
apachetomcat
9.0.0:milestone13
apachetomcat
9.0.0:milestone14
apachetomcat
9.0.0:milestone15
apachetomcat
9.0.0:milestone16
apachetomcat
9.0.0:milestone17
apachetomcat
9.0.0:milestone18
apachetomcat
9.0.0:milestone19
apachetomcat
9.0.0:milestone20
apachetomcat
9.0.0:milestone21
apachetomcat
9.0.0:milestone22
apachetomcat
9.0.0:milestone23
apachetomcat
9.0.0:milestone24
apachetomcat
9.0.0:milestone25
apachetomcat
9.0.0:milestone26
apachetomcat
9.0.0:milestone27
apachetomcat
9.0.0:milestone5
apachetomcat
9.0.0:milestone6
apachetomcat
9.0.0:milestone7
apachetomcat
9.0.0:milestone8
apachetomcat
9.0.0:milestone9
apachetomcat
9.0.1
apachetomcat
9.0.2
apachetomcat
9.0.3
apachetomcat
9.0.4
apachetomcat
9.0.5
apachetomcat
9.0.6
apachetomcat
9.0.7
apachetomcat
9.0.8
apachetomcat
9.0.9
apachetomcat
9.0.10
apachetomcat
9.0.11
apachetomcat
9.0.12
apachetomcat
9.0.13
apachetomcat
9.0.14
apachetomcat
9.0.15
apachetomcat
9.0.16
apachetomcat
9.0.17
apachetomcat
9.0.18
apachetomcat
9.0.19
apachetomcat
9.0.20
apachetomcat
9.0.21
apachetomcat
9.0.22
apachetomcat
9.0.23
apachetomcat
9.0.24
apachetomcat
9.0.25
apachetomcat
9.0.26
apachetomcat
9.0.27
apachetomcat
9.0.28
apachetomcat
9.0.29
apachetomcat
9.0.30
apachetomcat
9.0.31
apachetomcat
9.0.32
apachetomcat
9.0.33
apachetomcat
9.0.34
apachetomcat
9.0.35
apachetomcat
9.0.36
apachetomcat
9.0.37
apachetomcat
10.0.0:milestone1
apachetomcat
10.0.0:milestone2
apachetomcat
10.0.0:milestone3
apachetomcat
10.0.0:milestone4
apachetomcat
10.0.0:milestone5
apachetomcat
10.0.0:milestone6
apachetomcat
10.0.0:milestone7
debiandebian_linux
9.0
debiandebian_linux
10.0
oracleinstantis_enterprisetrack
17.1
oracleinstantis_enterprisetrack
17.2
oracleinstantis_enterprisetrack
17.3
oraclesd-wan_edge
9.0
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
tomcat9
bullseye
9.0.43-2~deb11u10
fixed
bullseye (security)
9.0.43-2~deb11u10
fixed
bookworm
9.0.70-2
fixed
sid
9.0.95-1
fixed
trixie
9.0.95-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
tomcat8
focal
dne
bionic
not-affected
xenial
not-affected
trusty
dne
tomcat9
focal
not-affected
bionic
not-affected
xenial
dne
trusty
dne