SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2020-17527

While this would most likely lead to an error and the closure of the HTTP/2 connection, it is possible that information could leak between requests.

HIGH 7.5EPSS 24.6%

Does this matter?

EPSS puts the probability of exploitation in the next 30 days at 24.6%, higher than 98% of all known CVEs. Patch or mitigate before the next change window.

Description

While investigating bug 64830 it was discovered that Apache Tomcat 10.0.0-M1 to 10.0.0-M9, 9.0.0-M1 to 9.0.39 and 8.5.0 to 8.5.59 could re-use an HTTP request header value from the previous stream received on an HTTP/2 connection for the request associated with the subsequent stream. While this would most likely lead to an error and the closure of the HTTP/2 connection, it is possible that information could leak between requests.

CVSS 3.1
7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS
24.62% probability · 98th percentile
CISA KEV
Not listed
Weakness
CWE-200
Affected
apache/tomcat · netapp/element plug-in · netapp/oncommand system manager · debian/debian linux · oracle/blockchain platform · oracle/communications cloud native core binding support function · oracle/communications cloud native core policy · oracle/communications instant messaging server · oracle/instantis enterprisetrack · oracle/mysql enterprise monitor · oracle/sd-wan edge · oracle/workload manager
Source
security@apache.org

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.