Impact
A race condition in a threaded component of Apache Tomcat Native can cause client‑certificate verification requirements to be lowered. The flaw means that, under certain configurations, the server may accept a weaker or even no client certificate during TLS mutual authentication. Based on the description, this could allow an attacker to establish a privileged connection that would normally be rejected, potentially compromising authentication integrity.
Affected Systems
Apache Tomcat Native versions 2.0.0 through 2.0.15 and 1.3.0 through 1.3.8 are affected. Unsupported releases may also be impacted. Users running any of these versions should assume that the vulnerability is present until an update is applied.
Risk and Exploitability
The flaw is classified under CWE‑366 but no CVSS score is provided; the EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog. Consequently, the documented severity remains unspecified. The description suggests that a successful exploitation would enable the use of weak or missing client certificates, which could lead to unauthorized access. No public exploits have been reported, and the lack of an EPSS score indicates that exploitation probability is unknown at this time.
OpenCVE Enrichment