← Back

CVE-2018-8037

nvd nist
Published: Aug 2, 2018Modified: Jun 17, 2026

JSON object

Loading...
5.9
Vector
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Exploitability: 2.2 / Impact: 3.6
Source: NVD

Description

If an async request was completed by the application at the same time as the container triggered the async timeout, a race condition existed that could result in a user seeing a response intended for a different user. An additional issue was present in the NIO and NIO2 connectors that did not correctly track the closure of the connection when an async request was completed by the application and timed out by the container at the same time. This could also result in a user seeing a response intended for another user. Versions Affected: Apache Tomcat 9.0.0.M9 to 9.0.9 and 8.5.5 to 8.5.31.

Affected (23)

1 product
Tomcat
1 product
Debian Linux
Configuration A
22 vulnerable
Vulnerable SoftwareAffected Versions
Apache
From 8.5.5 to 8.5.31
From 9.0.1 to 9.0.9
Version 9.0.0
Version 9.0.0 milestone10
Version 9.0.0 milestone11
Version 9.0.0 milestone12
Version 9.0.0 milestone13
Version 9.0.0 milestone14
Version 9.0.0 milestone15
Version 9.0.0 milestone16
Version 9.0.0 milestone17
Version 9.0.0 milestone18
Version 9.0.0 milestone19
Version 9.0.0 milestone20
Version 9.0.0 milestone21
Version 9.0.0 milestone22
Version 9.0.0 milestone23
Version 9.0.0 milestone24
Version 9.0.0 milestone25
Version 9.0.0 milestone26
Version 9.0.0 milestone27
Version 9.0.0 milestone9
Configuration B
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 9.0

References (52)

Source: security@apache.org
PatchThird Party Advisory
Source: security@apache.org
Third Party AdvisoryVDB Entry
Source: security@apache.org
Third Party AdvisoryVDB Entry
Source: security@apache.org
Third Party Advisory
Source: security@apache.org
Third Party Advisory
Source: security@apache.org
Third Party Advisory
Source: security@apache.org
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.