CVE-2020-13934: Improper Restriction of Operations within the Bounds of a Memory Buffer in Apache Tomcat
7.5
CVSS Score
3.1
Basic Information
CVE ID
GHSA ID
EPSS Score
0.95589%
CWE
Published
2/8/2022
Updated
2/1/2023
KEV Status
No
Technology
Java
Technical Details
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
---|---|---|---|
org.apache.tomcat:tomcat | maven | >= 10.0.0-M1, <= 10.0.0-M5 | 10.0.0-M6 |
org.apache.tomcat:tomcat | maven | >= 9.0.0.M5, < 9.0.36 | 9.0.36 |
org.apache.tomcat:tomcat | maven | >= 8.5.1, < 8.5.56 | 8.5.56 |
Vulnerability Intelligence
Miggo AI
Root Cause Analysis
The analysis is based on the description of the vulnerability and the likely involvement of HTTP/2
and HTTP/1.1
handling in Apache Tomcat
. The exact function names are inferred based on typical Tomcat
architecture and the nature of the vulnerability.