QID 730041
Date Published: 2021-04-15
QID 730041: Apache Tomcat Duplicate Request Headers Vulnerabilities
Apache Tomcat is an open source web server and servlet container developed by the Apache Software Foundation.
CVE-2021-25122: When responding to new h2c connection requests, Apache Tomcat could duplicate request headers and a limited amount of request body from one request to another meaning user A and user B could both see the results of user A's request.
Affected Versions:
Apache Tomcat 9.0.0.M1 to 9.0.41
QID Detection Logic (Unauthenticated):
The QID checks for vulnerable version by sending a GET /QUALYS13827 HTTP/1.0 request which helps in retrieving the installed version of Apache Tomcat in the banner of the response.
Apache Tomcat could duplicate request headers and a limited amount of request body from one request to another meaning user A and user B could both see the results of user A's request.
- Apache_Tomcat_9.0.43 -
tomcat.apache.org/security-9.html#Fixed_in_Apache_Tomcat_9.0.43
CVEs related to QID 730041
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| Fixed_in_Apache_Tomcat_9.0.43 |
|