CVE-2020-13943: Infoleak
A flaw was found in Apache Tomcat. If an HTTP/2 client exceeded the agreed maximum number of concurrent streams for a connection (in violation of the HTTP/2 protocol), it is possible that a subsequent request made on that connection could contain HTTP headers - including HTTP/2 pseudo headers - from a previous request rather than the intended headers. This could lead to users seeing responses for unexpected resources. The highest threat from this vulnerability is to data confidentiality.
Other sources
Apache Tomcat could allow a remote attacker to obtain sensitive information, caused by a flaw when HTTP/2 client exceeded the agreed maximum number of concurrent streams for a connection. By sending a specially-crafted HTTP request, an attacker could exploit this vulnerability to see the responses for unexpected resources, and use this information to launch further attacks against the affected system.
— IBM
If an HTTP/2 client connecting to Apache Tomcat 10.0.0-M1 to 10.0.0-M7, 9.0.0.M1 to 9.0.37 or 8.5.0 to 8.5.57 exceeded the agreed maximum number of concurrent streams for a connection (in violation of the HTTP/2 protocol), it was possible that a subsequent request made on that connection could contain HTTP headers - including HTTP/2 pseudo headers - from a previous request rather than the intended headers. This could lead to users seeing responses for unexpected resources.
If an HTTP/2 client exceeded the agreed maximum number of concurrent streams for a connection (in violation of the HTTP/2 protocol), it was possible that a subsequent request made on that connection could contain HTTP headers - including HTTP/2 pseudo headers - from a previous request rather than the intended headers. This could lead to users seeing responses for unexpected resources.
Upstream commits: Tomcat 10.0: https://github.com/apache/tomcat/commit/1bbc650cbc3f08d85a1ec6d803c47ae53a84f3bb Tomcat 9.0: https://github.com/apache/tomcat/commit/55911430df13f8c9998fbdee1f9716994d2db59b Tomcat 8.5: https://github.com/apache/tomcat/commit/9d7def063b47407a09a2f9202beed99f4dcb292a
Reference: http://mail-archives.apache.org/modmbox/tomcat-announce/202010.mbox/%3C2b767c6e-dcb9-5816-bd69-a3bc0771fef3%40apache.org%3E
— Red Hat
Affected Software
Remediation
Patch Available
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the severity of CVE-2020-13943?
CVE-2020-13943 has been rated as a medium severity vulnerability.
How do I fix CVE-2020-13943?
To mitigate CVE-2020-13943, upgrade to Apache Tomcat version 8.5.58, 9.0.38, or 10.0.0-M8.
Which versions of Apache Tomcat are affected by CVE-2020-13943?
CVE-2020-13943 affects Apache Tomcat versions from 8.5.0 to 8.5.57, and from 9.0.0-M1 to 9.0.37.
What is the main issue described in CVE-2020-13943?
CVE-2020-13943 involves an issue where HTTP/2 clients can exceed the maximum number of concurrent streams leading to header leakage.
Which products are impacted by CVE-2020-13943?
CVE-2020-13943 impacts Apache Tomcat as well as IBM® Engineering Requirements Management DOORS and its Web Access version.