CVE-2020-17527
HIGHApache Tomcat <10.0.0-M9, 9.0.39, 8.5.59 - Info Disclosure
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2020-17527. PoCs published by forse01.
AI-analyzed exploit summary The repository appears to be a stub or incomplete PoC for CVE-2020-17527, containing only standard Tomcat configuration files and no exploit code. The README is empty, and no offensive techniques are present.
Description
While investigating bug 64830 it was discovered that Apache Tomcat 10.0.0-M1 to 10.0.0-M9, 9.0.0-M1 to 9.0.39 and 8.5.0 to 8.5.59 could re-use an HTTP request header value from the previous stream received on an HTTP/2 connection for the request associated with the subsequent stream. While this would most likely lead to an error and the closure of the HTTP/2 connection, it is possible that information could leak between requests.
Exploits (1)
The repository appears to be a stub or incomplete PoC for CVE-2020-17527, containing only standard Tomcat configuration files and no exploit code. The README is empty, and no offensive techniques are present.
References (24)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N