Resource management error in Apache Tomcat - CVE-2020-13943
Published: October 12, 2020
Vulnerability details
The vulnerability allows a remote attacker to gain access to sensitive information.
The vulnerability exists due to improper management of internal resources within the application when processing HTTP/2 requests. If an HTTP/2 client exceeded the agreed maximum number of concurrent streams for a connection (in violation of the HTTP/2 protocol), it was possible that a subsequent request made on that connection could contain HTTP headers - including HTTP/2 pseudo headers - from a previous request rather than the intended headers. This could lead to users seeing responses for unexpected resources.
Affected software
tomcat9 (Debian package)
libtomcat9-embed-java (Ubuntu package)
tomcat9-common (Ubuntu package)
libtomcat9-java (Ubuntu package)
tomcat9 (Ubuntu package)
IBM Engineering Requirements Management DOORS Next
Oracle Solaris
Opensuse
Ubuntu
Dell PowerPath Management Appliance
Fuse
How to mitigate CVE-2020-13943
tomcat9 (Debian package) - update to 9.0.31-1~deb10u3
IBM Engineering Requirements Management DOORS Next - update to 9.7.2.8
Dell PowerPath Management Appliance - update to 3.2
Fuse - update to 7.10.0
libtomcat9-embed-java (Ubuntu package) - addressed in versions 9.0.16-3ubuntu0.18.04.2, 9.0.31-1ubuntu0.2
tomcat9-common (Ubuntu package) - addressed in versions 9.0.16-3ubuntu0.18.04.2, 9.0.31-1ubuntu0.2
libtomcat9-java (Ubuntu package) - addressed in versions 9.0.16-3ubuntu0.18.04.2, 9.0.31-1ubuntu0.2
tomcat9 (Ubuntu package) - addressed in versions 9.0.16-3ubuntu0.18.04.2, 9.0.31-1ubuntu0.2
External References
Related Security Bulletins
- Information disclosure in Apache Tomcat
- OpenSUSE Linux update for tomcat
- OpenSUSE Linux update for tomcat
- Multiple vulnerabilities in Oracle Solaris
- Debian update for tomcat9
- Ubuntu update for tomcat9
- Multiple vulnerabilities in PowerPath Management Appliance
- Multiple vulnerabilities in IBM Engineering Requirements Management DOORS/DWA
- Multiple vulnerabilities in Fuse 7.10