• CVE-2022-25762

发布时间: 2024年11月15日

修改时间: 2024年11月22日

概要

If a web application sends a WebSocket message concurrently with the WebSocket connection closing when running on Apache Tomcat 8.5.0 to 8.5.75 or Apache Tomcat 9.0.0.M1 to 9.0.20, it is possible that the application will continue to use the socket after it has been closed. The error handling triggered in this case could cause the a pooled object to be placed in the pool twice. This could result in subsequent connections using the same object concurrently which could result in data being returned to the wrong use and/or other errors.

CVSS v3 指标

NVD openEuler
CVSS评分 8.6 8.6
Attack Vector Network Network
Attack Complexity Low Low
Privileges Required None None
User Interaction None None
Scope Unchanged Unchanged
Confidentiality High High
Integrity Low Low
Availability Low Low

安全公告

公告名 概要 发布时间
KylinSec-SA-2024-4172 tomcat security update 2024年11月15日
KylinSec-SA-2024-4210 tomcat security update 2024年11月15日
KylinSec-SA-2024-5005 tomcat security update 2024年11月22日

影响产品

产品 状态
KY3.4-5A tomcat Fixed
KY3.5.2 tomcat Fixed
V6 tomcat Fixed