CVE-2021-25122
When responding to new h2c connection requests, Apache Tomcat versions 10.0.0-M1 to 10.0.0, 9.0.0.M1 to 9.0.41 and 8.5.0 to 8.5.61 could duplicate request headers and a limited amount of request body from one request to another meaning user A and user B could both see the results of user A's request.
- Affected products
- Alt Linux, Apache Tomcat, Astra Linux, Linuxmint, Suse, Ubuntu
- Apache Tomcat
- ≤ 8.5.61, 9.0.41, 9.0.0, 10.0.0
- Fix
- Available
- CVSS 3.1
- 7.5 HIGH
- EPSS
- 18.1% (97th percentile)
- Weakness
- CWE-200
- NVD status
- Modified
- Published
- 2021-03-01
CVE-2021-25122 at NVD
1 known exploit for CVE-2021-25122
Proof-of-concept code and exploit modules indexed by Sploitus