Resource management error in Apache Tomcat - CVE-2020-13943

 

Resource management error in Apache Tomcat - CVE-2020-13943

Published: October 12, 2020


Vulnerability identifier: #VU47516
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-13943
CWE-ID: CWE-399
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain access to sensitive information.

The vulnerability exists due to improper management of internal resources within the application when processing HTTP/2 requests. If an HTTP/2 client exceeded the agreed maximum number of concurrent streams for a connection (in violation of the HTTP/2 protocol), it was possible that a subsequent request made on that connection could contain HTTP headers - including HTTP/2 pseudo headers - from a previous request rather than the intended headers. This could lead to users seeing responses for unexpected resources.


Affected software

Apache Tomcat
tomcat9 (Debian package)
libtomcat9-embed-java (Ubuntu package)
tomcat9-common (Ubuntu package)
libtomcat9-java (Ubuntu package)
tomcat9 (Ubuntu package)
IBM Engineering Requirements Management DOORS Next
Oracle Solaris
Opensuse
Ubuntu
Dell PowerPath Management Appliance
Fuse

How to mitigate CVE-2020-13943

Install updates from vendor's website.

Apache Tomcat - addressed in versions 8.5.58, 9.0.38, 10.0.0-M8
tomcat9 (Debian package) - update to 9.0.31-1~deb10u3
IBM Engineering Requirements Management DOORS Next - update to 9.7.2.8
Dell PowerPath Management Appliance - update to 3.2
Fuse - update to 7.10.0
libtomcat9-embed-java (Ubuntu package) - addressed in versions 9.0.16-3ubuntu0.18.04.2, 9.0.31-1ubuntu0.2
tomcat9-common (Ubuntu package) - addressed in versions 9.0.16-3ubuntu0.18.04.2, 9.0.31-1ubuntu0.2
libtomcat9-java (Ubuntu package) - addressed in versions 9.0.16-3ubuntu0.18.04.2, 9.0.31-1ubuntu0.2
tomcat9 (Ubuntu package) - addressed in versions 9.0.16-3ubuntu0.18.04.2, 9.0.31-1ubuntu0.2

External References

Related Security Bulletins