Aller au contenu

Fiche vulnérabilité

CVE-2022-25762 : faille élevée Apache Software Foundation Apache Tomcat (CVSS 8.6)

Description

If a web application sends a WebSocket message concurrently with the WebSocket connection closing when running on Apache Tomcat 8.5.0 to 8.5.75 or Apache Tomcat 9.0.0.M1 to 9.0.20, it is possible that the application will continue to use the socket after it has been closed. The error handling triggered in this case could cause the a pooled object to be placed in the pool twice. This could result in subsequent connections using the same object concurrently which could result in data being returned to the wrong use and/or other errors.

En bref

Sévérité
Élevée (CVSS 8.6)
Vecteur CVSS
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L
Exploitation active
Non signalée par la CISA
Publication
13 mai 2022
Dernière mise à jour
3 août 2024

Produits concernés

  • Apache Software Foundation Apache Tomcat

Références

Rechercher une autre vulnérabilité dans la base CVE