CVE-2020-17527

CVSS V2 Medium 5 CVSS V3 High 7.5
Description
While investigating bug 64830 it was discovered that Apache Tomcat 10.0.0-M1 to 10.0.0-M9, 9.0.0-M1 to 9.0.39 and 8.5.0 to 8.5.59 could re-use an HTTP request header value from the previous stream received on an HTTP/2 connection for the request associated with the subsequent stream. While this would most likely lead to an error and the closure of the HTTP/2 connection, it is possible that information could leak between requests.
Overview
  • CVE ID
  • CVE-2020-17527
  • Assigner
  • security@apache.org
  • Vulnerability Status
  • Analyzed
  • Published Version
  • 2020-12-03T19:15:12
  • Last Modified Date
  • 2022-05-12T14:47:33
CPE Configuration (Product)
CPE Vulnerable Operator Version Start Version End
cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:* 1 OR 8.5.1 8.5.59
cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:* 1 OR 9.0.1 9.0.35
cpe:2.3:a:apache:tomcat:9.0.0:milestone10:*:*:*:*:*:* 1 OR
cpe:2.3:a:apache:tomcat:9.0.0:milestone11:*:*:*:*:*:* 1 OR
cpe:2.3:a:apache:tomcat:9.0.0:milestone12:*:*:*:*:*:* 1 OR
cpe:2.3:a:apache:tomcat:9.0.0:milestone13:*:*:*:*:*:* 1 OR
cpe:2.3:a:apache:tomcat:9.0.0:milestone14:*:*:*:*:*:* 1 OR
cpe:2.3:a:apache:tomcat:9.0.0:milestone15:*:*:*:*:*:* 1 OR
cpe:2.3:a:apache:tomcat:9.0.0:milestone16:*:*:*:*:*:* 1 OR
cpe:2.3:a:apache:tomcat:9.0.0:milestone17:*:*:*:*:*:* 1 OR
cpe:2.3:a:apache:tomcat:9.0.0:milestone18:*:*:*:*:*:* 1 OR
cpe:2.3:a:apache:tomcat:9.0.0:milestone19:*:*:*:*:*:* 1 OR
cpe:2.3:a:apache:tomcat:9.0.0:milestone20:*:*:*:*:*:* 1 OR
cpe:2.3:a:apache:tomcat:9.0.0:milestone21:*:*:*:*:*:* 1 OR
cpe:2.3:a:apache:tomcat:9.0.0:milestone22:*:*:*:*:*:* 1 OR
cpe:2.3:a:apache:tomcat:9.0.0:milestone23:*:*:*:*:*:* 1 OR
cpe:2.3:a:apache:tomcat:9.0.0:milestone24:*:*:*:*:*:* 1 OR
cpe:2.3:a:apache:tomcat:9.0.0:milestone25:*:*:*:*:*:* 1 OR
cpe:2.3:a:apache:tomcat:9.0.0:milestone26:*:*:*:*:*:* 1 OR
cpe:2.3:a:apache:tomcat:9.0.0:milestone27:*:*:*:*:*:* 1 OR
cpe:2.3:a:apache:tomcat:9.0.0:milestone5:*:*:*:*:*:* 1 OR
cpe:2.3:a:apache:tomcat:9.0.0:milestone6:*:*:*:*:*:* 1 OR
cpe:2.3:a:apache:tomcat:9.0.0:milestone7:*:*:*:*:*:* 1 OR
cpe:2.3:a:apache:tomcat:9.0.0:milestone8:*:*:*:*:*:* 1 OR
cpe:2.3:a:apache:tomcat:9.0.0:milestone9:*:*:*:*:*:* 1 OR
cpe:2.3:a:apache:tomcat:9.0.35-3.39.1:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:apache:tomcat:9.0.35-3.57.3:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:apache:tomcat:9.0.36:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:apache:tomcat:9.0.37:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:apache:tomcat:9.0.38:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:apache:tomcat:9.0.39:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:apache:tomcat:10.0.0:milestone1:*:*:*:*:*:* 1 OR
cpe:2.3:a:apache:tomcat:10.0.0:milestone2:*:*:*:*:*:* 1 OR
cpe:2.3:a:apache:tomcat:10.0.0:milestone3:*:*:*:*:*:* 1 OR
cpe:2.3:a:apache:tomcat:10.0.0:milestone4:*:*:*:*:*:* 1 OR
cpe:2.3:a:apache:tomcat:10.0.0:milestone5:*:*:*:*:*:* 1 OR
cpe:2.3:a:apache:tomcat:10.0.0:milestone6:*:*:*:*:*:* 1 OR
cpe:2.3:a:apache:tomcat:10.0.0:milestone7:*:*:*:*:*:* 1 OR
cpe:2.3:a:apache:tomcat:10.0.0:milestone8:*:*:*:*:*:* 1 OR
cpe:2.3:a:apache:tomcat:10.0.0:milestone9:*:*:*:*:*:* 1 OR
cpe:2.3:a:netapp:element_plug-in:-:*:*:*:*:vcenter_server:*:* 1 OR
cpe:2.3:a:netapp:oncommand_system_manager:*:*:*:*:*:*:*:* 1 OR 3.0.0 3.1.3
cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:* 1 OR
cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:oracle:blockchain_platform:*:*:*:*:*:*:*:* 1 OR 21.1.2
cpe:2.3:a:oracle:communications_cloud_native_core_binding_support_function:1.10.0:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:oracle:communications_cloud_native_core_policy:1.14.0:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:oracle:communications_instant_messaging_server:10.0.1.5.0:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:oracle:instantis_enterprisetrack:17.1:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:oracle:instantis_enterprisetrack:17.2:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:oracle:instantis_enterprisetrack:17.3:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:oracle:mysql_enterprise_monitor:*:*:*:*:*:*:*:* 1 OR 8.0.23
cpe:2.3:a:oracle:sd-wan_edge:9.0:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:oracle:workload_manager:18c:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:oracle:workload_manager:19c:*:*:*:*:*:*:* 1 OR
CVSS Version 2
  • Version
  • 2.0
  • Vector String
  • AV:N/AC:L/Au:N/C:P/I:N/A:N
  • Access Vector
  • NETWORK
  • Access Compatibility
  • LOW
  • Authentication
  • NONE
  • Confidentiality Impact
  • PARTIAL
  • Integrity Impact
  • NONE
  • Availability Impact
  • NONE
  • Base Score
  • 5
  • Severity
  • MEDIUM
  • Exploitability Score
  • 10
  • Impact Score
  • 2.9
CVSS Version 3
  • Version
  • 3.1
  • Vector String
  • CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
  • Attack Vector
  • NETWORK
  • Attack Compatibility
  • LOW
  • Privileges Required
  • NONE
  • User Interaction
  • NONE
  • Scope
  • UNCHANGED
  • Confidentiality Impact
  • HIGH
  • Availability Impact
  • NONE
  • Base Score
  • 7.5
  • Base Severity
  • HIGH
  • Exploitability Score
  • 3.9
  • Impact Score
  • 3.6
References
Reference URL Reference Tags
https://lists.apache.org/thread.html/rce5ac9a40173651d540babce59f6f3825f12c6d4e886ba00823b11e5%40%3Cannounce.tomcat.apache.org%3E Mailing List Vendor Advisory
https://lists.apache.org/thread.html/rce5ac9a40173651d540babce59f6f3825f12c6d4e886ba00823b11e5@%3Cannounce.tomcat.apache.org%3E Mailing List Vendor Advisory
https://lists.apache.org/thread.html/rce5ac9a40173651d540babce59f6f3825f12c6d4e886ba00823b11e5@%3Cannounce.apache.org%3E Mailing List Vendor Advisory
https://lists.apache.org/thread.html/raa0e9ad388c1e6fd1e301b5e080f9439f64cb4178119a86a4801cc53@%3Cdev.tomcat.apache.org%3E Mailing List Vendor Advisory
https://lists.apache.org/thread.html/rd5babd13d7a350b369b2f647b4dd32ce678af42f9aba5389df1ae6ca@%3Cusers.tomcat.apache.org%3E Mailing List Vendor Advisory
https://lists.apache.org/thread.html/r8a227ac6a755a6406c1cc47dd48800e973d4cf13fe7fe68ac59c679c@%3Cdev.tomcat.apache.org%3E Mailing List Vendor Advisory
http://www.openwall.com/lists/oss-security/2020/12/03/3 Mailing List Third Party Advisory
https://lists.apache.org/thread.html/rabbe6b3ae6a9795641d7a05c00d2378d5bbbe4240b7e20f09b092cce@%3Cissues.guacamole.apache.org%3E Mailing List Vendor Advisory
https://lists.apache.org/thread.html/ra35c8d617b17d59f400112cebadec43ad379f98198b4a9726190d7ee@%3Cissues.guacamole.apache.org%3E Mailing List Vendor Advisory
https://lists.apache.org/thread.html/r9fd47f1b03e9b41d16a5cf72659b533887267d3398d963c2fff3abfa@%3Ccommits.tomee.apache.org%3E Mailing List Vendor Advisory
https://lists.apache.org/thread.html/r26a2a66339087fc37db3caf201e446d3e83b5cce314371e235ff1784@%3Ccommits.tomee.apache.org%3E Mailing List Vendor Advisory
https://security.netapp.com/advisory/ntap-20201210-0003/ Third Party Advisory
https://lists.debian.org/debian-lts-announce/2020/12/msg00022.html Mailing List Third Party Advisory
https://security.gentoo.org/glsa/202012-23 Third Party Advisory
https://lists.apache.org/thread.html/rca833c6d42b7b9ce1563488c0929f29fcc95947d86e5e740258c8937@%3Cdev.tomcat.apache.org%3E Mailing List Vendor Advisory
https://lists.apache.org/thread.html/ra9fcdb904dd2e2256ef90b3e4ced279cd464cb0ab63a6c64df5c010d@%3Cannounce.apache.org%3E Mailing List Vendor Advisory
https://lists.apache.org/thread.html/rbba08c4dcef3603e36276d49adda8eedbe458c5104314b4038f697e1@%3Cusers.tomcat.apache.org%3E Mailing List Vendor Advisory
https://lists.apache.org/thread.html/ra9fcdb904dd2e2256ef90b3e4ced279cd464cb0ab63a6c64df5c010d@%3Cannounce.tomcat.apache.org%3E Mailing List Vendor Advisory
https://lists.apache.org/thread.html/r5a285242737ddef4d338236328aaaf3237183e1465a5efafd16b99ed@%3Cdev.tomcat.apache.org%3E Mailing List Vendor Advisory
https://www.debian.org/security/2021/dsa-4835 Third Party Advisory
https://lists.apache.org/thread.html/r2d6e05c5ff96f8068a59dfdb3800e9ee8d4e36ce1971783c6e5f9b20@%3Ccommits.tomee.apache.org%3E Mailing List Vendor Advisory
https://www.oracle.com/security-alerts/cpuApr2021.html Patch Third Party Advisory
https://www.oracle.com//security-alerts/cpujul2021.html Patch Third Party Advisory
https://www.oracle.com/security-alerts/cpujan2022.html Patch Third Party Advisory
https://www.oracle.com/security-alerts/cpuapr2022.html
History
Created Old Value New Value Data Type Notes
2022-04-20 16:59:54 Added to TrackCVE
2022-12-05 17:35:50 2020-12-03T19:15Z 2020-12-03T19:15:12 CVE Published Date updated
2022-12-05 17:35:50 2022-05-12T14:47:33 CVE Modified Date updated
2022-12-05 17:35:50 Analyzed Vulnerability Status updated