Lucene search

K
f5F5F5:K41102235
HistoryOct 18, 2022 - 12:00 a.m.

K41102235 : Tomcat vulnerability CVE-2021-43980

2022-10-1800:00:00
my.f5.com
24
tomcat
vulnerability
concurrency

AI Score

4

Confidence

High

EPSS

0.002

Percentile

58.5%

Security Advisory Description

The simplified implementation of blocking reads and writes introduced in Tomcat 10 and back-ported to Tomcat 9.0.47 onwards exposed a long standing (but extremely hard to trigger) concurrency bug in Apache Tomcat 10.1.0 to 10.1.0-M12, 10.0.0-M1 to 10.0.18, 9.0.0-M1 to 9.0.60 and 8.5.0 to 8.5.77 that could cause client connections to share an Http11Processor instance resulting in responses, or part responses, to be received by the wrong client. (CVE-2021-43980)

Impact

There is no impact; F5 products are not affected by this vulnerability.