If an HTTP/2 client connecting to Apache Tomcat 10.0.0-M1 to 10.0.0-M7, 9.0.0.M1 to 9.0.37 or 8.5.0 to 8.5.57 exceeded the agreed maximum number of concurrent streams for a connection (in violation of the HTTP/2 protocol), it was possible that a subsequent request made on that connection could contain HTTP headers - including HTTP/2 pseudo headers - from a previous request rather than the intended headers. This could lead to users seeing responses for unexpected resources.
{
"versions": [
{
"introduced": "0"
},
{
"last_affected": "8.5.0"
},
{
"introduced": "0"
},
{
"last_affected": "8.5.1"
},
{
"introduced": "0"
},
{
"last_affected": "8.5.2"
},
{
"introduced": "0"
},
{
"last_affected": "8.5.3"
},
{
"introduced": "0"
},
{
"last_affected": "8.5.4"
},
{
"introduced": "0"
},
{
"last_affected": "8.5.5"
},
{
"introduced": "0"
},
{
"last_affected": "8.5.6"
},
{
"introduced": "0"
},
{
"last_affected": "8.5.7"
},
{
"introduced": "0"
},
{
"last_affected": "8.5.8"
},
{
"introduced": "0"
},
{
"last_affected": "8.5.9"
},
{
"introduced": "0"
},
{
"last_affected": "8.5.10"
},
{
"introduced": "0"
},
{
"last_affected": "8.5.11"
},
{
"introduced": "0"
},
{
"last_affected": "8.5.12"
},
{
"introduced": "0"
},
{
"last_affected": "8.5.13"
},
{
"introduced": "0"
},
{
"last_affected": "8.5.14"
},
{
"introduced": "0"
},
{
"last_affected": "8.5.15"
},
{
"introduced": "0"
},
{
"last_affected": "8.5.16"
},
{
"introduced": "0"
},
{
"last_affected": "8.5.17"
},
{
"introduced": "0"
},
{
"last_affected": "8.5.18"
},
{
"introduced": "0"
},
{
"last_affected": "8.5.19"
},
{
"introduced": "0"
},
{
"last_affected": "8.5.20"
},
{
"introduced": "0"
},
{
"last_affected": "8.5.21"
},
{
"introduced": "0"
},
{
"last_affected": "8.5.22"
},
{
"introduced": "0"
},
{
"last_affected": "8.5.23"
},
{
"introduced": "0"
},
{
"last_affected": "8.5.24"
},
{
"introduced": "0"
},
{
"last_affected": "8.5.25"
},
{
"introduced": "0"
},
{
"last_affected": "8.5.26"
},
{
"introduced": "0"
},
{
"last_affected": "8.5.27"
},
{
"introduced": "0"
},
{
"last_affected": "8.5.28"
},
{
"introduced": "0"
},
{
"last_affected": "8.5.29"
},
{
"introduced": "0"
},
{
"last_affected": "8.5.30"
},
{
"introduced": "0"
},
{
"last_affected": "8.5.31"
},
{
"introduced": "0"
},
{
"last_affected": "8.5.32"
},
{
"introduced": "0"
},
{
"last_affected": "8.5.33"
},
{
"introduced": "0"
},
{
"last_affected": "8.5.34"
},
{
"introduced": "0"
},
{
"last_affected": "8.5.35"
},
{
"introduced": "0"
},
{
"last_affected": "8.5.36"
},
{
"introduced": "0"
},
{
"last_affected": "8.5.37"
},
{
"introduced": "0"
},
{
"last_affected": "8.5.38"
},
{
"introduced": "0"
},
{
"last_affected": "8.5.39"
},
{
"introduced": "0"
},
{
"last_affected": "8.5.40"
},
{
"introduced": "0"
},
{
"last_affected": "8.5.41"
},
{
"introduced": "0"
},
{
"last_affected": "8.5.42"
},
{
"introduced": "0"
},
{
"last_affected": "8.5.43"
},
{
"introduced": "0"
},
{
"last_affected": "8.5.44"
},
{
"introduced": "0"
},
{
"last_affected": "8.5.45"
},
{
"introduced": "0"
},
{
"last_affected": "8.5.46"
},
{
"introduced": "0"
},
{
"last_affected": "8.5.47"
},
{
"introduced": "0"
},
{
"last_affected": "8.5.48"
},
{
"introduced": "0"
},
{
"last_affected": "8.5.49"
},
{
"introduced": "0"
},
{
"last_affected": "8.5.50"
},
{
"introduced": "0"
},
{
"last_affected": "8.5.51"
},
{
"introduced": "0"
},
{
"last_affected": "8.5.52"
},
{
"introduced": "0"
},
{
"last_affected": "8.5.53"
},
{
"introduced": "0"
},
{
"last_affected": "8.5.54"
},
{
"introduced": "0"
},
{
"last_affected": "8.5.55"
},
{
"introduced": "0"
},
{
"last_affected": "8.5.56"
},
{
"introduced": "0"
},
{
"last_affected": "8.5.57"
},
{
"introduced": "0"
},
{
"last_affected": "9.0.0-milestone10"
},
{
"introduced": "0"
},
{
"last_affected": "9.0.0-milestone11"
},
{
"introduced": "0"
},
{
"last_affected": "9.0.0-milestone12"
},
{
"introduced": "0"
},
{
"last_affected": "9.0.0-milestone13"
},
{
"introduced": "0"
},
{
"last_affected": "9.0.0-milestone14"
},
{
"introduced": "0"
},
{
"last_affected": "9.0.0-milestone15"
},
{
"introduced": "0"
},
{
"last_affected": "9.0.0-milestone16"
},
{
"introduced": "0"
},
{
"last_affected": "9.0.0-milestone17"
},
{
"introduced": "0"
},
{
"last_affected": "9.0.0-milestone18"
},
{
"introduced": "0"
},
{
"last_affected": "9.0.0-milestone19"
},
{
"introduced": "0"
},
{
"last_affected": "9.0.0-milestone20"
},
{
"introduced": "0"
},
{
"last_affected": "9.0.0-milestone21"
},
{
"introduced": "0"
},
{
"last_affected": "9.0.0-milestone22"
},
{
"introduced": "0"
},
{
"last_affected": "9.0.0-milestone23"
},
{
"introduced": "0"
},
{
"last_affected": "9.0.0-milestone24"
},
{
"introduced": "0"
},
{
"last_affected": "9.0.0-milestone25"
},
{
"introduced": "0"
},
{
"last_affected": "9.0.0-milestone26"
},
{
"introduced": "0"
},
{
"last_affected": "9.0.0-milestone27"
},
{
"introduced": "0"
},
{
"last_affected": "9.0.0-milestone5"
},
{
"introduced": "0"
},
{
"last_affected": "9.0.0-milestone6"
},
{
"introduced": "0"
},
{
"last_affected": "9.0.0-milestone7"
},
{
"introduced": "0"
},
{
"last_affected": "9.0.0-milestone8"
},
{
"introduced": "0"
},
{
"last_affected": "9.0.0-milestone9"
},
{
"introduced": "0"
},
{
"last_affected": "9.0.1"
},
{
"introduced": "0"
},
{
"last_affected": "9.0.2"
},
{
"introduced": "0"
},
{
"last_affected": "9.0.3"
},
{
"introduced": "0"
},
{
"last_affected": "9.0.4"
},
{
"introduced": "0"
},
{
"last_affected": "9.0.5"
},
{
"introduced": "0"
},
{
"last_affected": "9.0.6"
},
{
"introduced": "0"
},
{
"last_affected": "9.0.7"
},
{
"introduced": "0"
},
{
"last_affected": "9.0.8"
},
{
"introduced": "0"
},
{
"last_affected": "9.0.9"
},
{
"introduced": "0"
},
{
"last_affected": "9.0.10"
},
{
"introduced": "0"
},
{
"last_affected": "9.0.11"
},
{
"introduced": "0"
},
{
"last_affected": "9.0.12"
},
{
"introduced": "0"
},
{
"last_affected": "9.0.13"
},
{
"introduced": "0"
},
{
"last_affected": "9.0.14"
},
{
"introduced": "0"
},
{
"last_affected": "9.0.15"
},
{
"introduced": "0"
},
{
"last_affected": "9.0.16"
},
{
"introduced": "0"
},
{
"last_affected": "9.0.17"
},
{
"introduced": "0"
},
{
"last_affected": "9.0.18"
},
{
"introduced": "0"
},
{
"last_affected": "9.0.19"
},
{
"introduced": "0"
},
{
"last_affected": "9.0.20"
},
{
"introduced": "0"
},
{
"last_affected": "9.0.21"
},
{
"introduced": "0"
},
{
"last_affected": "9.0.22"
},
{
"introduced": "0"
},
{
"last_affected": "9.0.23"
},
{
"introduced": "0"
},
{
"last_affected": "9.0.24"
},
{
"introduced": "0"
},
{
"last_affected": "9.0.25"
},
{
"introduced": "0"
},
{
"last_affected": "9.0.26"
},
{
"introduced": "0"
},
{
"last_affected": "9.0.27"
},
{
"introduced": "0"
},
{
"last_affected": "9.0.28"
},
{
"introduced": "0"
},
{
"last_affected": "9.0.29"
},
{
"introduced": "0"
},
{
"last_affected": "9.0.30"
},
{
"introduced": "0"
},
{
"last_affected": "9.0.31"
},
{
"introduced": "0"
},
{
"last_affected": "9.0.32"
},
{
"introduced": "0"
},
{
"last_affected": "9.0.33"
},
{
"introduced": "0"
},
{
"last_affected": "9.0.34"
},
{
"introduced": "0"
},
{
"last_affected": "9.0.35"
},
{
"introduced": "0"
},
{
"last_affected": "9.0.36"
},
{
"introduced": "0"
},
{
"last_affected": "9.0.37"
},
{
"introduced": "0"
},
{
"last_affected": "10.0.0-milestone1"
},
{
"introduced": "0"
},
{
"last_affected": "10.0.0-milestone2"
},
{
"introduced": "0"
},
{
"last_affected": "10.0.0-milestone3"
},
{
"introduced": "0"
},
{
"last_affected": "10.0.0-milestone4"
},
{
"introduced": "0"
},
{
"last_affected": "10.0.0-milestone5"
},
{
"introduced": "0"
},
{
"last_affected": "10.0.0-milestone6"
},
{
"introduced": "0"
},
{
"last_affected": "10.0.0-milestone7"
},
{
"introduced": "0"
},
{
"last_affected": "9.0"
},
{
"introduced": "0"
},
{
"last_affected": "10.0"
},
{
"introduced": "0"
},
{
"last_affected": "9.0"
}
]
}"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-13943.json"
[
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "17.1"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "17.2"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "17.3"
}
]
}
]