{"schema_version":"1.7.3","id":"GHSA-jx7c-7mj5-9438","published":"2022-09-29T00:00:25Z","modified":"2024-03-11T16:46:19.307324Z","aliases":["BIT-tomcat-2021-43980","CVE-2021-43980"],"summary":"Apache Tomcat Race Condition vulnerability","details":"The simplified implementation of blocking reads and writes introduced in Tomcat 10 and back-ported to Tomcat 9.0.47 onwards exposed a long standing (but extremely hard to trigger) concurrency bug in Apache Tomcat 10.1.0 to 10.1.0-M12, 10.0.0-M1 to 10.0.18, 9.0.0-M1 to 9.0.60 and 8.5.0 to 8.5.77 that could cause client connections to share an Http11Processor instance resulting in responses, or part responses, to be received by the wrong client.","affected":[{"package":{"name":"org.apache.tomcat:tomcat","ecosystem":"Maven","purl":"pkg:maven/org.apache.tomcat/tomcat"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"8.5.0"},{"fixed":"8.5.78"}]}],"versions":["8.5.0","8.5.11","8.5.12","8.5.13","8.5.14","8.5.15","8.5.16","8.5.19","8.5.2","8.5.20","8.5.21","8.5.23","8.5.24","8.5.27","8.5.28","8.5.29","8.5.3","8.5.30","8.5.31","8.5.32","8.5.33","8.5.34","8.5.35","8.5.37","8.5.38","8.5.39","8.5.4","8.5.40","8.5.41","8.5.42","8.5.43","8.5.45","8.5.46","8.5.47","8.5.49","8.5.5","8.5.50","8.5.51","8.5.53","8.5.54","8.5.55","8.5.56","8.5.57","8.5.58","8.5.59","8.5.6","8.5.60","8.5.61","8.5.63","8.5.64","8.5.65","8.5.66","8.5.68","8.5.69","8.5.70","8.5.71","8.5.72","8.5.73","8.5.75","8.5.76","8.5.77","8.5.8","8.5.9"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/09/GHSA-jx7c-7mj5-9438/GHSA-jx7c-7mj5-9438.json"}},{"package":{"name":"org.apache.tomcat:tomcat","ecosystem":"Maven","purl":"pkg:maven/org.apache.tomcat/tomcat"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"9.0.0-M1"},{"fixed":"9.0.62"}]}],"versions":["9.0.0.M1","9.0.0.M10","9.0.0.M11","9.0.0.M13","9.0.0.M15","9.0.0.M17","9.0.0.M18","9.0.0.M19","9.0.0.M20","9.0.0.M21","9.0.0.M22","9.0.0.M25","9.0.0.M26","9.0.0.M27","9.0.0.M3","9.0.0.M4","9.0.0.M6","9.0.0.M8","9.0.0.M9","9.0.1","9.0.10","9.0.11","9.0.12","9.0.13","9.0.14","9.0.16","9.0.17","9.0.19","9.0.2","9.0.20","9.0.21","9.0.22","9.0.24","9.0.26","9.0.27","9.0.29","9.0.30","9.0.31","9.0.33","9.0.34","9.0.35","9.0.36","9.0.37","9.0.38","9.0.39","9.0.4","9.0.40","9.0.41","9.0.43","9.0.44","9.0.45","9.0.46","9.0.48","9.0.5","9.0.50","9.0.52","9.0.53","9.0.54","9.0.55","9.0.56","9.0.58","9.0.59","9.0.6","9.0.60","9.0.7","9.0.8"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/09/GHSA-jx7c-7mj5-9438/GHSA-jx7c-7mj5-9438.json"}},{"package":{"name":"org.apache.tomcat:tomcat","ecosystem":"Maven","purl":"pkg:maven/org.apache.tomcat/tomcat"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"10.0.0-M1"},{"fixed":"10.0.20"}]}],"versions":["10.0.0","10.0.0-M1","10.0.0-M10","10.0.0-M3","10.0.0-M4","10.0.0-M5","10.0.0-M6","10.0.0-M7","10.0.0-M8","10.0.0-M9","10.0.10","10.0.11","10.0.12","10.0.13","10.0.14","10.0.16","10.0.17","10.0.18","10.0.2","10.0.4","10.0.5","10.0.6","10.0.7","10.0.8"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/09/GHSA-jx7c-7mj5-9438/GHSA-jx7c-7mj5-9438.json"}},{"package":{"name":"org.apache.tomcat:tomcat","ecosystem":"Maven","purl":"pkg:maven/org.apache.tomcat/tomcat"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"10.1.0-M1"},{"fixed":"10.1.0-M14"}]}],"versions":["10.1.0-M1","10.1.0-M10","10.1.0-M11","10.1.0-M12","10.1.0-M2","10.1.0-M4","10.1.0-M5","10.1.0-M6","10.1.0-M7","10.1.0-M8"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/09/GHSA-jx7c-7mj5-9438/GHSA-jx7c-7mj5-9438.json"}}],"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2021-43980"},{"type":"WEB","url":"https://github.com/apache/tomcat/commit/170e0f792bd18ff031677890ba2fe50eb7a376c1"},{"type":"WEB","url":"https://github.com/apache/tomcat/commit/17f177eeb7df5938f67ef9ea580411b120195f13"},{"type":"WEB","url":"https://github.com/apache/tomcat/commit/4a00b0c0890538b9d3107eef8f2e0afadd119beb"},{"type":"WEB","url":"https://github.com/apache/tomcat/commit/9651b83a1d04583791525e5f0c4c9089f678d9fc"},{"type":"PACKAGE","url":"https://github.com/apache/tomcat"},{"type":"WEB","url":"https://lists.apache.org/thread/3jjqbsp6j88b198x5rmg99b1qr8ht3g3"},{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2022/10/msg00029.html"},{"type":"WEB","url":"https://tomcat.apache.org/security-10.html"},{"type":"WEB","url":"https://tomcat.apache.org/security-8.html"},{"type":"WEB","url":"https://tomcat.apache.org/security-9.html"},{"type":"WEB","url":"https://www.debian.org/security/2022/dsa-5265"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2022/09/28/1"}],"database_specific":{"cwe_ids":["CWE-362"],"github_reviewed":true,"github_reviewed_at":"2022-09-30T06:30:10Z","nvd_published_at":"2022-09-28T14:15:00Z","severity":"LOW"},"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N"}]}