Junglewise Threat Intelligence

CVE-2021-25122: Apache Tomcat information disclosure in h2c connection handling

CVE-2021-25122 · Severity: high · CVSS 7.5 · Published 2021-06-16

Technologies: Apache Tomcat-Embed-Core, Apache Tomcat-Coyote, Apache Tomcat. Vendors: Apache.

Executive brief

Apache Tomcat, a widely used web server for Java applications, contains a flaw in how it handles certain HTTP/2 connection requests. This vulnerability could allow an unauthorized user to see sensitive information, such as headers or parts of the request body, belonging to another user's session. This could lead to the exposure of private data or session credentials.

Technical details

An information disclosure vulnerability exists in Apache Tomcat's handling of HTTP/2 over cleartext (h2c) upgrade requests. When processing new h2c connections, the server may incorrectly duplicate request headers and a limited portion of the request body from one connection to another. This allows an attacker or an unrelated user to view data intended for a different request. The issue affects versions 8.5.x, 9.0.x, and 10.0.x and is categorized as CWE-200. Patches have been released in versions 8.5.63, 9.0.43, and 10.0.2.

Affected products

  • Apache Tomcat 8.5.0 to 8.5.61, 9.0.0.M1 to 9.0.41, 10.0.0-M1 to 10.0.0
  • Apache tomcat-embed-core >= 8.5.0, < 8.5.63; >= 9.0.0-M1, < 9.0.43; >= 10.0.0-M1, < 10.0.2
  • Apache tomcat-coyote >= 10.0.0-M1, < 10.0.2

Timeline

  • 2021-03-01: disclosed
  • 2021-03-01: advisory: NVD publication date
  • 2021-06-16: other: GitHub Advisory published

References