Back

HIGH

tomcat: Incorrect handling of pipelined requests when send file was used

Published Apr 17, 2017

Description

A bug in the handling of the pipelined requests in Apache Tomcat 9.0.0.M1 to 9.0.0.M18, 8.5.0 to 8.5.12, 8.0.0.RC1 to 8.0.42, 7.0.0 to 7.0.76, and 6.0.0 to 6.0.52, when send file was used, results in the pipelined request being lost when send file processing of the previous request completed. This could result in responses appearing to be sent for the wrong request. For example, a user agent that sent requests A, B and C could see the correct response for request A, the response for request C for request B and no response for request C.

Affected products

Remediation

Red Hat mitigation

The AJP connector does not support the sendfile capability. A server configured to only use the AJP connector (disable HTTP Connector) is not affected by this vulnerability. Disable the sendfile capability by setting useSendfile="false" in the HTTP connector configuration. Note: Disabling sendfile, may impact performance on large files.

Metrics

References (63)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner apache
Published Apr 17, 2017
Updated Aug 5, 2024
Reserved Jan 29, 2017
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Important
Public date Apr 10, 2017
GHSA-3GV7-3H64-78CM