If an HTTP/2 client connecting to Apache Tomcat 10.0.0-M1 to 10.0.0-M7, 9.0.0.M1 to 9.0.37 or 8.5.0 to 8.5.57 exceeded the agreed maximum number of concurrent streams for a connection (in violation of the HTTP/2 protocol), it was possible that a subsequent request made on that connection could contain HTTP headers - including HTTP/2 pseudo headers - from a previous request rather than the intended headers. This could lead to users seeing responses for unexpected resources.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: apache
Published: 2020-10-12T13:46:47
Updated: 2024-08-04T12:32:14.470Z
Reserved: 2020-06-08T00:00:00
Link: CVE-2020-13943
Vulnrichment
No data.
NVD
Status : Analyzed
Published: 2020-10-12T14:15:12.183
Modified: 2023-01-31T21:44:33.870
Link: CVE-2020-13943
Redhat