CVE-2021-43980

CVSS V2 None CVSS V3 Low 3.7
Description
The simplified implementation of blocking reads and writes introduced in Tomcat 10 and back-ported to Tomcat 9.0.47 onwards exposed a long standing (but extremely hard to trigger) concurrency bug in Apache Tomcat 10.1.0 to 10.1.0-M12, 10.0.0-M1 to 10.0.18, 9.0.0-M1 to 9.0.60 and 8.5.0 to 8.5.77 that could cause client connections to share an Http11Processor instance resulting in responses, or part responses, to be received by the wrong client.
Overview
  • CVE ID
  • CVE-2021-43980
  • Assigner
  • security@apache.org
  • Vulnerability Status
  • Analyzed
  • Published Version
  • 2022-09-28T14:15:09
  • Last Modified Date
  • 2022-11-10T04:00:03
CPE Configuration (Product)
CPE Vulnerable Operator Version Start Version End
cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:* 1 OR 8.5.0 8.5.77
cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:* 1 OR 9.0.0 9.0.60
cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:* 1 OR 10.0.0 10.0.18
cpe:2.3:a:apache:tomcat:10.1.0:milestone1:*:*:*:*:*:* 1 OR
cpe:2.3:a:apache:tomcat:10.1.0:milestone10:*:*:*:*:*:* 1 OR
cpe:2.3:a:apache:tomcat:10.1.0:milestone11:*:*:*:*:*:* 1 OR
cpe:2.3:a:apache:tomcat:10.1.0:milestone12:*:*:*:*:*:* 1 OR
cpe:2.3:a:apache:tomcat:10.1.0:milestone2:*:*:*:*:*:* 1 OR
cpe:2.3:a:apache:tomcat:10.1.0:milestone3:*:*:*:*:*:* 1 OR
cpe:2.3:a:apache:tomcat:10.1.0:milestone4:*:*:*:*:*:* 1 OR
cpe:2.3:a:apache:tomcat:10.1.0:milestone5:*:*:*:*:*:* 1 OR
cpe:2.3:a:apache:tomcat:10.1.0:milestone6:*:*:*:*:*:* 1 OR
cpe:2.3:a:apache:tomcat:10.1.0:milestone7:*:*:*:*:*:* 1 OR
cpe:2.3:a:apache:tomcat:10.1.0:milestone8:*:*:*:*:*:* 1 OR
cpe:2.3:a:apache:tomcat:10.1.0:milestone9:*:*:*:*:*:* 1 OR
cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:* 1 OR
cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:* 1 OR
CVSS Version 3
  • Version
  • 3.1
  • Vector String
  • CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
  • Attack Vector
  • NETWORK
  • Attack Compatibility
  • HIGH
  • Privileges Required
  • NONE
  • User Interaction
  • NONE
  • Scope
  • UNCHANGED
  • Confidentiality Impact
  • LOW
  • Availability Impact
  • NONE
  • Base Score
  • 3.7
  • Base Severity
  • LOW
  • Exploitability Score
  • 2.2
  • Impact Score
  • 1.4
References
History
Created Old Value New Value Data Type Notes
2022-09-28 16:00:09 Added to TrackCVE
2022-12-07 05:03:51 2022-09-28T14:15Z 2022-09-28T14:15:09 CVE Published Date updated
2022-12-07 05:03:51 2022-11-10T04:00:03 CVE Modified Date updated
2022-12-07 05:03:51 Analyzed Vulnerability Status updated
2022-12-07 05:03:56 References updated