QID 730013

Date Published: 2021-04-05

QID 730013: Apache Tomcat HTTP2 Client Information Disclosure Vulnerability(CVE-2020-13943)

Apache Tomcat is an open source web server and servlet container developed by the Apache Software Foundation.
If an HTTP/2 client exceeded the agreed maximum number of concurrent streams for a connection (in violation of the HTTP/2 protocol), it was possible that a subsequent request made on that connection could contain HTTP headers - including HTTP/2 pseudo headers - from a previous request rather than the intended headers. This could lead to users seeing responses for unexpected resources.

Affected Versions:
Apache Tomcat 10.0.0-M1 to 10.0.0-M7 Apache Tomcat 9.0.0.M5 to 9.0.37 Apache Tomcat 8.5.1 to 8.5.57 QID Detection Logic:
The QID checks for vulnerable version by sending a GET /QUALYS13813 HTTP/1.0 request which helps in retrieving the installed version of Apache Tomcat in the banner of the response.

This vulnerability could be exploited to gain access to sensitive information.

  • CVSS V3 rated as Medium - 4.3 severity.
  • CVSS V2 rated as Medium - 4 severity.
  • Solution
    Upgrade to the Apache Tomcat 10.0.0-M8, 9.0.38,8.5.58 or later version. Please refer to Apache Tomcat Website.

    CVEs related to QID 730013

    Software Advisories
    Advisory ID Software Component Link
    Apache Tomcat URL Logo lists.apache.org/thread.html/r4a390027eb27e4550142fac6c8317cc684b157ae314d31514747f307%40%3Cannounce.tomcat.apache.org%3E