Back

CRITICAL

tomcat: Incorrect handling of send file processing could result into adding Processort to the cache twice

Published Apr 17, 2017

Description

In Apache Tomcat 9.0.0.M1 to 9.0.0.M18 and 8.5.0 to 8.5.12, the refactoring of the HTTP connectors introduced a regression in the send file processing. If the send file processing completed quickly, it was possible for the Processor to be added to the processor cache twice. This could result in the same Processor being used for multiple requests which in turn could lead to unexpected errors and/or response mix-up.

Affected products

Remediation

No remediation recorded yet.

Metrics

Weaknesses (1)

References (34)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner apache
Published Apr 17, 2017
Updated Aug 5, 2024
Reserved Jan 29, 2017
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Important
Public date Apr 10, 2017
GHSA-9HG2-395J-83RM