CVE-2020-13943 (CNNVD-202010-415)

MEDIUM
中文标题:
Apache Tomcat 安全漏洞
英文标题:
If an HTTP/2 client connecting to Apache Tomcat 10.0.0-M1 to 10.0.0-M7, 9.0.0.M1 to 9.0.37 or 8.5.0 ...
CVSS分数: 4.3
发布时间: 2020-10-12 13:46:47
漏洞类型: 其他
状态: PUBLISHED
数据质量分数: 0.30
数据版本: v3
漏洞描述
中文描述:

Apache Tomcat是美国阿帕奇(Apache)基金会的一款轻量级Web应用服务器。该程序实现了对Servlet和JavaServer Page(JSP)的支持。 Apache Tomcat存在安全漏洞,该漏洞源于如果一个HTTP/2客户端连接到超过约定的最大数量的并发流连接(违反HTTP / 2协议),它是可能的后续请求在该连接可以包含HTTP头信息,包括HTTP / 2伪头,从先前的请求而不是标题。这可能导致用户看到对意外资源的响应。以下产品及版本受到影响:10.0.0-M1版本至10.0.0-M7版本, 9.0.0.M1版本至9.0.37版本,8.5.0版本至8.5.57版本。

英文描述:

If an HTTP/2 client connecting to Apache Tomcat 10.0.0-M1 to 10.0.0-M7, 9.0.0.M1 to 9.0.37 or 8.5.0 to 8.5.57 exceeded the agreed maximum number of concurrent streams for a connection (in violation of the HTTP/2 protocol), it was possible that a subsequent request made on that connection could contain HTTP headers - including HTTP/2 pseudo headers - from a previous request rather than the intended headers. This could lead to users seeing responses for unexpected resources.

CWE类型:
(暂无数据)
标签:
(暂无数据)
受影响产品
厂商 产品 版本 版本范围 平台 CPE
apache tomcat 8.5.0 - - cpe:2.3:a:apache:tomcat:8.5.0:*:*:*:*:*:*:*
apache tomcat 8.5.1 - - cpe:2.3:a:apache:tomcat:8.5.1:*:*:*:*:*:*:*
apache tomcat 8.5.2 - - cpe:2.3:a:apache:tomcat:8.5.2:*:*:*:*:*:*:*
apache tomcat 8.5.3 - - cpe:2.3:a:apache:tomcat:8.5.3:*:*:*:*:*:*:*
apache tomcat 8.5.4 - - cpe:2.3:a:apache:tomcat:8.5.4:*:*:*:*:*:*:*
apache tomcat 8.5.5 - - cpe:2.3:a:apache:tomcat:8.5.5:*:*:*:*:*:*:*
apache tomcat 8.5.6 - - cpe:2.3:a:apache:tomcat:8.5.6:*:*:*:*:*:*:*
apache tomcat 8.5.7 - - cpe:2.3:a:apache:tomcat:8.5.7:*:*:*:*:*:*:*
apache tomcat 8.5.8 - - cpe:2.3:a:apache:tomcat:8.5.8:*:*:*:*:*:*:*
apache tomcat 8.5.9 - - cpe:2.3:a:apache:tomcat:8.5.9:*:*:*:*:*:*:*
apache tomcat 8.5.10 - - cpe:2.3:a:apache:tomcat:8.5.10:*:*:*:*:*:*:*
apache tomcat 8.5.11 - - cpe:2.3:a:apache:tomcat:8.5.11:*:*:*:*:*:*:*
apache tomcat 8.5.12 - - cpe:2.3:a:apache:tomcat:8.5.12:*:*:*:*:*:*:*
apache tomcat 8.5.13 - - cpe:2.3:a:apache:tomcat:8.5.13:*:*:*:*:*:*:*
apache tomcat 8.5.14 - - cpe:2.3:a:apache:tomcat:8.5.14:*:*:*:*:*:*:*
apache tomcat 8.5.15 - - cpe:2.3:a:apache:tomcat:8.5.15:*:*:*:*:*:*:*
apache tomcat 8.5.16 - - cpe:2.3:a:apache:tomcat:8.5.16:*:*:*:*:*:*:*
apache tomcat 8.5.17 - - cpe:2.3:a:apache:tomcat:8.5.17:*:*:*:*:*:*:*
apache tomcat 8.5.18 - - cpe:2.3:a:apache:tomcat:8.5.18:*:*:*:*:*:*:*
apache tomcat 8.5.19 - - cpe:2.3:a:apache:tomcat:8.5.19:*:*:*:*:*:*:*
apache tomcat 8.5.20 - - cpe:2.3:a:apache:tomcat:8.5.20:*:*:*:*:*:*:*
apache tomcat 8.5.21 - - cpe:2.3:a:apache:tomcat:8.5.21:*:*:*:*:*:*:*
apache tomcat 8.5.22 - - cpe:2.3:a:apache:tomcat:8.5.22:*:*:*:*:*:*:*
apache tomcat 8.5.23 - - cpe:2.3:a:apache:tomcat:8.5.23:*:*:*:*:*:*:*
apache tomcat 8.5.24 - - cpe:2.3:a:apache:tomcat:8.5.24:*:*:*:*:*:*:*
apache tomcat 8.5.25 - - cpe:2.3:a:apache:tomcat:8.5.25:*:*:*:*:*:*:*
apache tomcat 8.5.26 - - cpe:2.3:a:apache:tomcat:8.5.26:*:*:*:*:*:*:*
apache tomcat 8.5.27 - - cpe:2.3:a:apache:tomcat:8.5.27:*:*:*:*:*:*:*
apache tomcat 8.5.28 - - cpe:2.3:a:apache:tomcat:8.5.28:*:*:*:*:*:*:*
apache tomcat 8.5.29 - - cpe:2.3:a:apache:tomcat:8.5.29:*:*:*:*:*:*:*
apache tomcat 8.5.30 - - cpe:2.3:a:apache:tomcat:8.5.30:*:*:*:*:*:*:*
apache tomcat 8.5.31 - - cpe:2.3:a:apache:tomcat:8.5.31:*:*:*:*:*:*:*
apache tomcat 8.5.32 - - cpe:2.3:a:apache:tomcat:8.5.32:*:*:*:*:*:*:*
apache tomcat 8.5.33 - - cpe:2.3:a:apache:tomcat:8.5.33:*:*:*:*:*:*:*
apache tomcat 8.5.34 - - cpe:2.3:a:apache:tomcat:8.5.34:*:*:*:*:*:*:*
apache tomcat 8.5.35 - - cpe:2.3:a:apache:tomcat:8.5.35:*:*:*:*:*:*:*
apache tomcat 8.5.36 - - cpe:2.3:a:apache:tomcat:8.5.36:*:*:*:*:*:*:*
apache tomcat 8.5.37 - - cpe:2.3:a:apache:tomcat:8.5.37:*:*:*:*:*:*:*
apache tomcat 8.5.38 - - cpe:2.3:a:apache:tomcat:8.5.38:*:*:*:*:*:*:*
apache tomcat 8.5.39 - - cpe:2.3:a:apache:tomcat:8.5.39:*:*:*:*:*:*:*
apache tomcat 8.5.40 - - cpe:2.3:a:apache:tomcat:8.5.40:*:*:*:*:*:*:*
apache tomcat 8.5.41 - - cpe:2.3:a:apache:tomcat:8.5.41:*:*:*:*:*:*:*
apache tomcat 8.5.42 - - cpe:2.3:a:apache:tomcat:8.5.42:*:*:*:*:*:*:*
apache tomcat 8.5.43 - - cpe:2.3:a:apache:tomcat:8.5.43:*:*:*:*:*:*:*
apache tomcat 8.5.44 - - cpe:2.3:a:apache:tomcat:8.5.44:*:*:*:*:*:*:*
apache tomcat 8.5.45 - - cpe:2.3:a:apache:tomcat:8.5.45:*:*:*:*:*:*:*
apache tomcat 8.5.46 - - cpe:2.3:a:apache:tomcat:8.5.46:*:*:*:*:*:*:*
apache tomcat 8.5.47 - - cpe:2.3:a:apache:tomcat:8.5.47:*:*:*:*:*:*:*
apache tomcat 8.5.48 - - cpe:2.3:a:apache:tomcat:8.5.48:*:*:*:*:*:*:*
apache tomcat 8.5.49 - - cpe:2.3:a:apache:tomcat:8.5.49:*:*:*:*:*:*:*
apache tomcat 8.5.50 - - cpe:2.3:a:apache:tomcat:8.5.50:*:*:*:*:*:*:*
apache tomcat 8.5.51 - - cpe:2.3:a:apache:tomcat:8.5.51:*:*:*:*:*:*:*
apache tomcat 8.5.52 - - cpe:2.3:a:apache:tomcat:8.5.52:*:*:*:*:*:*:*
apache tomcat 8.5.53 - - cpe:2.3:a:apache:tomcat:8.5.53:*:*:*:*:*:*:*
apache tomcat 8.5.54 - - cpe:2.3:a:apache:tomcat:8.5.54:*:*:*:*:*:*:*
apache tomcat 8.5.55 - - cpe:2.3:a:apache:tomcat:8.5.55:*:*:*:*:*:*:*
apache tomcat 8.5.56 - - cpe:2.3:a:apache:tomcat:8.5.56:*:*:*:*:*:*:*
apache tomcat 8.5.57 - - cpe:2.3:a:apache:tomcat:8.5.57:*:*:*:*:*:*:*
apache tomcat 9.0.0 - - cpe:2.3:a:apache:tomcat:9.0.0:milestone10:*:*:*:*:*:*
apache tomcat 9.0.1 - - cpe:2.3:a:apache:tomcat:9.0.1:*:*:*:*:*:*:*
apache tomcat 9.0.2 - - cpe:2.3:a:apache:tomcat:9.0.2:*:*:*:*:*:*:*
apache tomcat 9.0.3 - - cpe:2.3:a:apache:tomcat:9.0.3:*:*:*:*:*:*:*
apache tomcat 9.0.4 - - cpe:2.3:a:apache:tomcat:9.0.4:*:*:*:*:*:*:*
apache tomcat 9.0.5 - - cpe:2.3:a:apache:tomcat:9.0.5:*:*:*:*:*:*:*
apache tomcat 9.0.6 - - cpe:2.3:a:apache:tomcat:9.0.6:*:*:*:*:*:*:*
apache tomcat 9.0.7 - - cpe:2.3:a:apache:tomcat:9.0.7:*:*:*:*:*:*:*
apache tomcat 9.0.8 - - cpe:2.3:a:apache:tomcat:9.0.8:*:*:*:*:*:*:*
apache tomcat 9.0.9 - - cpe:2.3:a:apache:tomcat:9.0.9:*:*:*:*:*:*:*
apache tomcat 9.0.10 - - cpe:2.3:a:apache:tomcat:9.0.10:*:*:*:*:*:*:*
apache tomcat 9.0.11 - - cpe:2.3:a:apache:tomcat:9.0.11:*:*:*:*:*:*:*
apache tomcat 9.0.12 - - cpe:2.3:a:apache:tomcat:9.0.12:*:*:*:*:*:*:*
apache tomcat 9.0.13 - - cpe:2.3:a:apache:tomcat:9.0.13:*:*:*:*:*:*:*
apache tomcat 9.0.14 - - cpe:2.3:a:apache:tomcat:9.0.14:*:*:*:*:*:*:*
apache tomcat 9.0.15 - - cpe:2.3:a:apache:tomcat:9.0.15:*:*:*:*:*:*:*
apache tomcat 9.0.16 - - cpe:2.3:a:apache:tomcat:9.0.16:*:*:*:*:*:*:*
apache tomcat 9.0.17 - - cpe:2.3:a:apache:tomcat:9.0.17:*:*:*:*:*:*:*
apache tomcat 9.0.18 - - cpe:2.3:a:apache:tomcat:9.0.18:*:*:*:*:*:*:*
apache tomcat 9.0.19 - - cpe:2.3:a:apache:tomcat:9.0.19:*:*:*:*:*:*:*
apache tomcat 9.0.20 - - cpe:2.3:a:apache:tomcat:9.0.20:*:*:*:*:*:*:*
apache tomcat 9.0.21 - - cpe:2.3:a:apache:tomcat:9.0.21:*:*:*:*:*:*:*
apache tomcat 9.0.22 - - cpe:2.3:a:apache:tomcat:9.0.22:*:*:*:*:*:*:*
apache tomcat 9.0.23 - - cpe:2.3:a:apache:tomcat:9.0.23:*:*:*:*:*:*:*
apache tomcat 9.0.24 - - cpe:2.3:a:apache:tomcat:9.0.24:*:*:*:*:*:*:*
apache tomcat 9.0.25 - - cpe:2.3:a:apache:tomcat:9.0.25:*:*:*:*:*:*:*
apache tomcat 9.0.26 - - cpe:2.3:a:apache:tomcat:9.0.26:*:*:*:*:*:*:*
apache tomcat 9.0.27 - - cpe:2.3:a:apache:tomcat:9.0.27:*:*:*:*:*:*:*
apache tomcat 9.0.28 - - cpe:2.3:a:apache:tomcat:9.0.28:*:*:*:*:*:*:*
apache tomcat 9.0.29 - - cpe:2.3:a:apache:tomcat:9.0.29:*:*:*:*:*:*:*
apache tomcat 9.0.30 - - cpe:2.3:a:apache:tomcat:9.0.30:*:*:*:*:*:*:*
apache tomcat 9.0.31 - - cpe:2.3:a:apache:tomcat:9.0.31:*:*:*:*:*:*:*
apache tomcat 9.0.32 - - cpe:2.3:a:apache:tomcat:9.0.32:*:*:*:*:*:*:*
apache tomcat 9.0.33 - - cpe:2.3:a:apache:tomcat:9.0.33:*:*:*:*:*:*:*
apache tomcat 9.0.34 - - cpe:2.3:a:apache:tomcat:9.0.34:*:*:*:*:*:*:*
apache tomcat 9.0.35 - - cpe:2.3:a:apache:tomcat:9.0.35:*:*:*:*:*:*:*
apache tomcat 9.0.36 - - cpe:2.3:a:apache:tomcat:9.0.36:*:*:*:*:*:*:*
apache tomcat 9.0.37 - - cpe:2.3:a:apache:tomcat:9.0.37:*:*:*:*:*:*:*
apache tomcat 10.0.0 - - cpe:2.3:a:apache:tomcat:10.0.0:milestone1:*:*:*:*:*:*
debian debian_linux 9.0 - - cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*
debian debian_linux 10.0 - - cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*
oracle instantis_enterprisetrack 17.1 - - cpe:2.3:a:oracle:instantis_enterprisetrack:17.1:*:*:*:*:*:*:*
oracle instantis_enterprisetrack 17.2 - - cpe:2.3:a:oracle:instantis_enterprisetrack:17.2:*:*:*:*:*:*:*
oracle instantis_enterprisetrack 17.3 - - cpe:2.3:a:oracle:instantis_enterprisetrack:17.3:*:*:*:*:*:*:*
oracle sd-wan_edge 9.0 - - cpe:2.3:a:oracle:sd-wan_edge:9.0:*:*:*:*:*:*:*
解决方案
中文解决方案:
(暂无数据)
英文解决方案:
(暂无数据)
临时解决方案:
(暂无数据)
参考链接
无标题 x_refsource_MISC
cve.org
访问
[debian-lts-announce] 20201014 [SECURITY] [DLA 2407-1] tomcat8 security update mailing-list
cve.org
访问
openSUSE-SU-2020:1799 vendor-advisory
cve.org
访问
openSUSE-SU-2020:1842 vendor-advisory
cve.org
访问
DSA-4835 vendor-advisory
cve.org
访问
无标题 x_refsource_MISC
cve.org
访问
无标题 x_refsource_CONFIRM
cve.org
访问
CVSS评分详情
4.3
MEDIUM
CVSS向量: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
CVSS版本: 3.1
机密性
LOW
完整性
NONE
可用性
NONE
时间信息
发布时间:
2020-10-12 13:46:47
修改时间:
2024-08-04 12:32:14
创建时间:
2025-11-11 15:36:02
更新时间:
2025-11-11 15:56:29
利用信息
暂无可利用代码信息
数据源详情
数据源 记录ID 版本 提取时间
CVE cve_CVE-2020-13943 2025-11-11 15:20:23 2025-11-11 07:36:02
NVD nvd_CVE-2020-13943 2025-11-11 14:57:04 2025-11-11 07:44:30
CNNVD cnnvd_CNNVD-202010-415 2025-11-11 15:10:30 2025-11-11 07:56:29
版本与语言
当前版本: v3
主要语言: EN
支持语言:
EN ZH
安全公告
暂无安全公告信息
变更历史
v3 CNNVD
2025-11-11 15:56:29
vulnerability_type: 未提取 → 其他; cnnvd_id: 未提取 → CNNVD-202010-415; data_sources: ['cve', 'nvd'] → ['cnnvd', 'cve', 'nvd']
查看详细变更
  • vulnerability_type: 未提取 -> 其他
  • cnnvd_id: 未提取 -> CNNVD-202010-415
  • data_sources: ['cve', 'nvd'] -> ['cnnvd', 'cve', 'nvd']
v2 NVD
2025-11-11 15:44:30
cvss_score: 未提取 → 4.3; cvss_vector: NOT_EXTRACTED → CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N; cvss_version: NOT_EXTRACTED → 3.1; affected_products_count: 0 → 103; data_sources: ['cve'] → ['cve', 'nvd']
查看详细变更
  • cvss_score: 未提取 -> 4.3
  • cvss_vector: NOT_EXTRACTED -> CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
  • cvss_version: NOT_EXTRACTED -> 3.1
  • affected_products_count: 0 -> 103
  • data_sources: ['cve'] -> ['cve', 'nvd']