CVE Database
/

CVE-2018-8037

Back to search

CVE-2018-8037

Published: Aug 2, 2018

Modified: Sep 16, 2024

PUBLISHED

Description

If an async request was completed by the application at the same time as the container triggered the async timeout, a race condition existed that could result in a user seeing a response intended for a different user. An additional issue was present in the NIO and NIO2 connectors that did not correctly track the closure of the connection when an async request was completed by the application and timed out by the container at the same time. This could also result in a user seeing a response intended for another user. Versions Affected: Apache Tomcat 9.0.0.M9 to 9.0.9 and 8.5.5 to 8.5.31.

VendorProductVersions

Apache Software Foundation

Apache Tomcat

affected
9.0.0.M9 to 9.0.9
affected
8.5.5 to 8.5.31

References

1041376
vdb-entry
x_refsource_SECTRACK
104894
vdb-entry
x_refsource_BID
DSA-4281
vendor-advisory
x_refsource_DEBIAN
RHSA-2018:2867
vendor-advisory
x_refsource_REDHAT
RHSA-2018:2868
vendor-advisory
x_refsource_REDHAT
RHSA-2019:1529
vendor-advisory
x_refsource_REDHAT

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now