Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:27564
HistoryOct 13, 2020 - 1:45 a.m.

HTTP/2 Request Mix-up

2020-10-1301:45:40
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
11

0.001 Low

EPSS

Percentile

42.1%

tomcat-coyote is vulnerable to authorization bypass. The vulnerability exists as requests could contain HTTP headers of a previous request rather than the intended headers, if a HTTP/2 client has exceeded the agreed maximum number of concurrent streams for a connection.

References