UBUNTU-CVE-2020-17527

    Dashboard / Vulnerabilities / UBUNTU-CVE-2020-17527

    UBUNTU-CVE-2020-17527

    Published: 3 Dec 2020Last Modified: 15 Jul 2026
    Upstream:
    Aliases:

    Summary:

    Details: While investigating bug 64830 it was discovered that Apache Tomcat 10.0.0-M1 to 10.0.0-M9, 9.0.0-M1 to 9.0.39 and 8.5.0 to 8.5.59 could re-use an HTTP request header value from the previous stream received on an HTTP/2 connection for the request associated with the subsequent stream. While this would most likely lead to an error and the closure of the HTTP/2 connection, it is possible that information could leak between requests.

    Affected packages

    Package

    Name: tomcat9

    Purl: pkg:deb/ubuntu/tomcat9?arch=source&distro=bionic

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -9.0.16-3ubuntu0.18.04.2

    Affected versions

    9.0.16-3~18.04.1
    9.0.16-3ubuntu0.18.04.1

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    UBUNTU-CVE-2020-17527 | CVE-DB