Author: markt
Date: Thu Dec  3 18:01:08 2020
New Revision: 1884073

URL: http://svn.apache.org/viewvc?rev=1884073&view=rev
Log:
Publish CVE-2020-17527

Modified:
    tomcat/site/trunk/docs/security-10.html
    tomcat/site/trunk/docs/security-8.html
    tomcat/site/trunk/docs/security-9.html
    tomcat/site/trunk/xdocs/security-10.xml
    tomcat/site/trunk/xdocs/security-8.xml
    tomcat/site/trunk/xdocs/security-9.xml

Modified: tomcat/site/trunk/docs/security-10.html
URL: 
http://svn.apache.org/viewvc/tomcat/site/trunk/docs/security-10.html?rev=1884073&r1=1884072&r2=1884073&view=diff
==============================================================================
--- tomcat/site/trunk/docs/security-10.html (original)
+++ tomcat/site/trunk/docs/security-10.html Thu Dec  3 18:01:08 2020
@@ -2,7 +2,7 @@
 <html lang="en"><head><META http-equiv="Content-Type" content="text/html; 
charset=UTF-8"><meta name="viewport" content="width=device-width, 
initial-scale=1"><link href="res/css/tomcat.css" rel="stylesheet" 
type="text/css"><link href="res/css/fonts/fonts.css" rel="stylesheet" 
type="text/css"><title>Apache Tomcat&reg; - Apache Tomcat 10 
vulnerabilities</title><meta name="author" content="Apache Tomcat 
Project"></head><body><div id="wrapper"><header id="header"><div 
class="clearfix"><div class="menu-toggler pull-left" tabindex="1"><div 
class="hamburger"></div></div><a href="http://tomcat.apache.org/";><img 
class="tomcat-logo pull-left noPrint" alt="Tomcat Home" 
src="res/images/tomcat.png"></a><h1 class="pull-left">Apache 
Tomcat<sup>&reg;</sup></h1><div class="asf-logos pull-right"><a 
href="https://www.apache.org/foundation/contributing.html"; target="_blank" 
class="pull-left"><img 
src="https://www.apache.org/images/SupportApache-small.png"; class="support-asf" 
alt="Support Apache"></a><a 
 href="http://www.apache.org/"; target="_blank" class="pull-left"><img 
src="res/images/asf_logo.svg" class="asf-logo" alt="The Apache Software 
Foundation"></a></div></div></header><main id="middle"><div><div 
id="mainLeft"><div id="nav-wrapper"><form 
action="https://www.google.com/search"; method="get"><div 
class="searchbox"><input value="tomcat.apache.org" name="sitesearch" 
type="hidden"><input aria-label="Search text" placeholder="Search&hellip;" 
required="required" name="q" id="query" 
type="search"><button>GO</button></div></form><div class="asfevents"><a 
href="https://www.apache.org/events/current-event.html";><img 
src="https://www.apache.org/events/current-event-234x60.png"; alt="Next ASF 
event"><br>
               Save the date!
             </a></div><nav><div><h2>Apache Tomcat</h2><ul><li><a 
href="./index.html">Home</a></li><li><a 
href="./taglibs.html">Taglibs</a></li><li><a href="./maven-plugin.html">Maven 
Plugin</a></li></ul></div><div><h2>Download</h2><ul><li><a 
href="./whichversion.html">Which version?</a></li><li><a 
href="https://tomcat.apache.org/download-10.cgi";>Tomcat 10 
(alpha)</a></li><li><a href="https://tomcat.apache.org/download-90.cgi";>Tomcat 
9</a></li><li><a href="https://tomcat.apache.org/download-80.cgi";>Tomcat 
8</a></li><li><a href="https://tomcat.apache.org/download-70.cgi";>Tomcat 
7</a></li><li><a 
href="https://tomcat.apache.org/download-connectors.cgi";>Tomcat 
Connectors</a></li><li><a 
href="https://tomcat.apache.org/download-native.cgi";>Tomcat 
Native</a></li><li><a 
href="https://tomcat.apache.org/download-taglibs.cgi";>Taglibs</a></li><li><a 
href="https://archive.apache.org/dist/tomcat/";>Archives</a></li></ul></div><div><h2>Documentation</h2><ul><li><a
 href="./tomcat-10.0-doc/index.html"
 >Tomcat 10.0 (alpha)</a></li><li><a href="./tomcat-9.0-doc/index.html">Tomcat 
 >9.0</a></li><li><a href="./tomcat-8.5-doc/index.html">Tomcat 
 >8.5</a></li><li><a href="./tomcat-7.0-doc/index.html">Tomcat 
 >7.0</a></li><li><a href="./connectors-doc/">Tomcat Connectors</a></li><li><a 
 >href="./native-doc/">Tomcat Native</a></li><li><a 
 >href="https://cwiki.apache.org/confluence/display/TOMCAT";>Wiki</a></li><li><a 
 >href="./migration.html">Migration Guide</a></li><li><a 
 >href="./presentations.html">Presentations</a></li><li><a 
 >href="https://cwiki.apache.org/confluence/x/Bi8lBg";>Specifications</a></li></ul></div><div><h2>Problems?</h2><ul><li><a
 > href="./security.html">Security Reports</a></li><li><a 
 >href="./findhelp.html">Find help</a></li><li><a 
 >href="https://cwiki.apache.org/confluence/display/TOMCAT/FAQ";>FAQ</a></li><li><a
 > href="./lists.html">Mailing Lists</a></li><li><a href="./bugreport.html">Bug 
 >Database</a></li><li><a href="./irc.html">IRC</a></li></ul></div><div><h2>Get 
 >Involved</h2><ul><li>
 <a href="./getinvolved.html">Overview</a></li><li><a 
href="./source.html">Source code</a></li><li><a 
href="./ci.html">Buildbot</a></li><li><a 
href="https://cwiki.apache.org/confluence/x/vIPzBQ";>Translations</a></li><li><a 
href="./tools.html">Tools</a></li></ul></div><div><h2>Media</h2><ul><li><a 
href="https://twitter.com/theapachetomcat";>Twitter</a></li><li><a 
href="https://www.youtube.com/c/ApacheTomcatOfficial";>YouTube</a></li><li><a 
href="https://blogs.apache.org/tomcat/";>Blog</a></li></ul></div><div><h2>Misc</h2><ul><li><a
 href="./whoweare.html">Who We Are</a></li><li><a 
href="https://www.redbubble.com/people/comdev/works/30885254-apache-tomcat";>Swag</a></li><li><a
 href="./heritage.html">Heritage</a></li><li><a 
href="http://www.apache.org";>Apache Home</a></li><li><a 
href="./resources.html">Resources</a></li><li><a 
href="./contact.html">Contact</a></li><li><a 
href="./legal.html">Legal</a></li><li><a 
href="https://www.apache.org/foundation/contributing.html";>Support 
Apache</a></li
 ><li><a 
 >href="https://www.apache.org/foundation/sponsorship.html";>Sponsorship</a></li><li><a
 > href="http://www.apache.org/foundation/thanks.html";>Thanks</a></li><li><a 
 >href="http://www.apache.org/licenses/";>License</a></li></ul></div></nav></div></div><div
 > id="mainRight"><div id="content"><h2 style="display: none;">Content</h2><h3 
 >id="Table_of_Contents">Table of Contents</h3><div class="text">
-<ul><li><a href="#Apache_Tomcat_10.x_vulnerabilities">Apache Tomcat 10.x 
vulnerabilities</a></li><li><a href="#Fixed_in_Apache_Tomcat_10.0.0-M8">Fixed 
in Apache Tomcat 10.0.0-M8</a></li><li><a 
href="#Fixed_in_Apache_Tomcat_10.0.0-M7">Fixed in Apache Tomcat 
10.0.0-M7</a></li><li><a href="#Fixed_in_Apache_Tomcat_10.0.0-M6">Fixed in 
Apache Tomcat 10.0.0-M6</a></li><li><a 
href="#Fixed_in_Apache_Tomcat_10.0.0-M5">Fixed in Apache Tomcat 
10.0.0-M5</a></li></ul>
+<ul><li><a href="#Apache_Tomcat_10.x_vulnerabilities">Apache Tomcat 10.x 
vulnerabilities</a></li><li><a href="#Fixed_in_Apache_Tomcat_10.0.0-M10">Fixed 
in Apache Tomcat 10.0.0-M10</a></li><li><a 
href="#Fixed_in_Apache_Tomcat_10.0.0-M8">Fixed in Apache Tomcat 
10.0.0-M8</a></li><li><a href="#Fixed_in_Apache_Tomcat_10.0.0-M7">Fixed in 
Apache Tomcat 10.0.0-M7</a></li><li><a 
href="#Fixed_in_Apache_Tomcat_10.0.0-M6">Fixed in Apache Tomcat 
10.0.0-M6</a></li><li><a href="#Fixed_in_Apache_Tomcat_10.0.0-M5">Fixed in 
Apache Tomcat 10.0.0-M5</a></li></ul>
 </div><h3 id="Apache_Tomcat_10.x_vulnerabilities">Apache Tomcat 10.x 
vulnerabilities</h3><div class="text">
     <p>This page lists all security vulnerabilities fixed in released versions
        of Apache Tomcat 10.x. Each vulnerability is given a
@@ -39,6 +39,27 @@
        <a href="security.html">Tomcat Security Team</a>. Thank you.
     </p>
 
+  </div><h3 id="Fixed_in_Apache_Tomcat_10.0.0-M10"><span class="pull-right">17 
November 2020</span> Fixed in Apache Tomcat 10.0.0-M10</h3><div class="text">
+
+    <p><strong>Moderate: HTTP/2 request header mix-up</strong>
+       <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-17527"; 
rel="nofollow">CVE-2020-17527</a></p>
+
+    <p>While investigating issue <a 
href="https://bz.apache.org/bugzilla/show_bug.cgi?id=64830";>64830</a> it was 
discovered that Apache
+       Tomcat could re-use an HTTP request header value from the previous 
stream
+       received on an HTTP/2 connection for the request associated with the
+       subsequent stream. While this would most likely lead to an error and the
+       closure of the HTTP/2 connection, it is possible that information could
+       leak between requests.
+    </p>
+
+    <p>This was fixed with commit
+       <a 
href="https://github.com/apache/tomcat/commit/8d2fe6894d6e258a6d615d7f786acca80e6020cb";>8d2fe689</a>.</p>
+
+    <p>This issue was identified by the Apache Tomcat Security team on 10
+       November 2020. The issue was made public on 3 December 2020.</p>
+
+    <p>Affects: 10.0.0-M1 to 10.0.0-M9</p>
+
   </div><h3 id="Fixed_in_Apache_Tomcat_10.0.0-M8"><span class="pull-right">14 
September 2020</span> Fixed in Apache Tomcat 10.0.0-M8</h3><div class="text">
 
     <p><strong>Moderate: HTTP/2 request mix-up</strong>

Modified: tomcat/site/trunk/docs/security-8.html
URL: 
http://svn.apache.org/viewvc/tomcat/site/trunk/docs/security-8.html?rev=1884073&r1=1884072&r2=1884073&view=diff
==============================================================================
--- tomcat/site/trunk/docs/security-8.html (original)
+++ tomcat/site/trunk/docs/security-8.html Thu Dec  3 18:01:08 2020
@@ -2,7 +2,7 @@
 <html lang="en"><head><META http-equiv="Content-Type" content="text/html; 
charset=UTF-8"><meta name="viewport" content="width=device-width, 
initial-scale=1"><link href="res/css/tomcat.css" rel="stylesheet" 
type="text/css"><link href="res/css/fonts/fonts.css" rel="stylesheet" 
type="text/css"><title>Apache Tomcat&reg; - Apache Tomcat 8 
vulnerabilities</title><meta name="author" content="Apache Tomcat 
Project"></head><body><div id="wrapper"><header id="header"><div 
class="clearfix"><div class="menu-toggler pull-left" tabindex="1"><div 
class="hamburger"></div></div><a href="http://tomcat.apache.org/";><img 
class="tomcat-logo pull-left noPrint" alt="Tomcat Home" 
src="res/images/tomcat.png"></a><h1 class="pull-left">Apache 
Tomcat<sup>&reg;</sup></h1><div class="asf-logos pull-right"><a 
href="https://www.apache.org/foundation/contributing.html"; target="_blank" 
class="pull-left"><img 
src="https://www.apache.org/images/SupportApache-small.png"; class="support-asf" 
alt="Support Apache"></a><a h
 ref="http://www.apache.org/"; target="_blank" class="pull-left"><img 
src="res/images/asf_logo.svg" class="asf-logo" alt="The Apache Software 
Foundation"></a></div></div></header><main id="middle"><div><div 
id="mainLeft"><div id="nav-wrapper"><form 
action="https://www.google.com/search"; method="get"><div 
class="searchbox"><input value="tomcat.apache.org" name="sitesearch" 
type="hidden"><input aria-label="Search text" placeholder="Search&hellip;" 
required="required" name="q" id="query" 
type="search"><button>GO</button></div></form><div class="asfevents"><a 
href="https://www.apache.org/events/current-event.html";><img 
src="https://www.apache.org/events/current-event-234x60.png"; alt="Next ASF 
event"><br>
               Save the date!
             </a></div><nav><div><h2>Apache Tomcat</h2><ul><li><a 
href="./index.html">Home</a></li><li><a 
href="./taglibs.html">Taglibs</a></li><li><a href="./maven-plugin.html">Maven 
Plugin</a></li></ul></div><div><h2>Download</h2><ul><li><a 
href="./whichversion.html">Which version?</a></li><li><a 
href="https://tomcat.apache.org/download-10.cgi";>Tomcat 10 
(alpha)</a></li><li><a href="https://tomcat.apache.org/download-90.cgi";>Tomcat 
9</a></li><li><a href="https://tomcat.apache.org/download-80.cgi";>Tomcat 
8</a></li><li><a href="https://tomcat.apache.org/download-70.cgi";>Tomcat 
7</a></li><li><a 
href="https://tomcat.apache.org/download-connectors.cgi";>Tomcat 
Connectors</a></li><li><a 
href="https://tomcat.apache.org/download-native.cgi";>Tomcat 
Native</a></li><li><a 
href="https://tomcat.apache.org/download-taglibs.cgi";>Taglibs</a></li><li><a 
href="https://archive.apache.org/dist/tomcat/";>Archives</a></li></ul></div><div><h2>Documentation</h2><ul><li><a
 href="./tomcat-10.0-doc/index.html"
 >Tomcat 10.0 (alpha)</a></li><li><a href="./tomcat-9.0-doc/index.html">Tomcat 
 >9.0</a></li><li><a href="./tomcat-8.5-doc/index.html">Tomcat 
 >8.5</a></li><li><a href="./tomcat-7.0-doc/index.html">Tomcat 
 >7.0</a></li><li><a href="./connectors-doc/">Tomcat Connectors</a></li><li><a 
 >href="./native-doc/">Tomcat Native</a></li><li><a 
 >href="https://cwiki.apache.org/confluence/display/TOMCAT";>Wiki</a></li><li><a 
 >href="./migration.html">Migration Guide</a></li><li><a 
 >href="./presentations.html">Presentations</a></li><li><a 
 >href="https://cwiki.apache.org/confluence/x/Bi8lBg";>Specifications</a></li></ul></div><div><h2>Problems?</h2><ul><li><a
 > href="./security.html">Security Reports</a></li><li><a 
 >href="./findhelp.html">Find help</a></li><li><a 
 >href="https://cwiki.apache.org/confluence/display/TOMCAT/FAQ";>FAQ</a></li><li><a
 > href="./lists.html">Mailing Lists</a></li><li><a href="./bugreport.html">Bug 
 >Database</a></li><li><a href="./irc.html">IRC</a></li></ul></div><div><h2>Get 
 >Involved</h2><ul><li>
 <a href="./getinvolved.html">Overview</a></li><li><a 
href="./source.html">Source code</a></li><li><a 
href="./ci.html">Buildbot</a></li><li><a 
href="https://cwiki.apache.org/confluence/x/vIPzBQ";>Translations</a></li><li><a 
href="./tools.html">Tools</a></li></ul></div><div><h2>Media</h2><ul><li><a 
href="https://twitter.com/theapachetomcat";>Twitter</a></li><li><a 
href="https://www.youtube.com/c/ApacheTomcatOfficial";>YouTube</a></li><li><a 
href="https://blogs.apache.org/tomcat/";>Blog</a></li></ul></div><div><h2>Misc</h2><ul><li><a
 href="./whoweare.html">Who We Are</a></li><li><a 
href="https://www.redbubble.com/people/comdev/works/30885254-apache-tomcat";>Swag</a></li><li><a
 href="./heritage.html">Heritage</a></li><li><a 
href="http://www.apache.org";>Apache Home</a></li><li><a 
href="./resources.html">Resources</a></li><li><a 
href="./contact.html">Contact</a></li><li><a 
href="./legal.html">Legal</a></li><li><a 
href="https://www.apache.org/foundation/contributing.html";>Support 
Apache</a></li
 ><li><a 
 >href="https://www.apache.org/foundation/sponsorship.html";>Sponsorship</a></li><li><a
 > href="http://www.apache.org/foundation/thanks.html";>Thanks</a></li><li><a 
 >href="http://www.apache.org/licenses/";>License</a></li></ul></div></nav></div></div><div
 > id="mainRight"><div id="content"><h2 style="display: none;">Content</h2><h3 
 >id="Table_of_Contents">Table of Contents</h3><div class="text">
-<ul><li><a href="#Apache_Tomcat_8.x_vulnerabilities">Apache Tomcat 8.x 
vulnerabilities</a></li><li><a href="#Fixed_in_Apache_Tomcat_8.5.58">Fixed in 
Apache Tomcat 8.5.58</a></li><li><a href="#Fixed_in_Apache_Tomcat_8.5.57">Fixed 
in Apache Tomcat 8.5.57</a></li><li><a 
href="#Fixed_in_Apache_Tomcat_8.5.56">Fixed in Apache Tomcat 
8.5.56</a></li><li><a href="#Fixed_in_Apache_Tomcat_8.5.55">Fixed in Apache 
Tomcat 8.5.55</a></li><li><a href="#Fixed_in_Apache_Tomcat_8.5.51">Fixed in 
Apache Tomcat 8.5.51</a></li><li><a href="#Fixed_in_Apache_Tomcat_8.5.50">Fixed 
in Apache Tomcat 8.5.50</a></li><li><a 
href="#Fixed_in_Apache_Tomcat_8.5.49">Fixed in Apache Tomcat 
8.5.49</a></li><li><a href="#Fixed_in_Apache_Tomcat_8.5.41">Fixed in Apache 
Tomcat 8.5.41</a></li><li><a href="#Fixed_in_Apache_Tomcat_8.5.40">Fixed in 
Apache Tomcat 8.5.40</a></li><li><a href="#Fixed_in_Apache_Tomcat_8.5.38">Fixed 
in Apache Tomcat 8.5.38</a></li><li><a 
href="#Fixed_in_Apache_Tomcat_8.5.34">Fixed in Apache Tomcat 8.5.
 34</a></li><li><a href="#Fixed_in_Apache_Tomcat_8.0.53">Fixed in Apache Tomcat 
8.0.53</a></li><li><a href="#Fixed_in_Apache_Tomcat_8.5.32">Fixed in Apache 
Tomcat 8.5.32</a></li><li><a href="#Fixed_in_Apache_Tomcat_8.0.52">Fixed in 
Apache Tomcat 8.0.52</a></li><li><a href="#Fixed_in_Apache_Tomcat_8.5.31">Fixed 
in Apache Tomcat 8.5.31</a></li><li><a 
href="#Fixed_in_Apache_Tomcat_8.0.50">Fixed in Apache Tomcat 
8.0.50</a></li><li><a href="#Fixed_in_Apache_Tomcat_8.5.28">Fixed in Apache 
Tomcat 8.5.28</a></li><li><a href="#Fixed_in_Apache_Tomcat_8.0.48">Fixed in 
Apache Tomcat 8.0.48</a></li><li><a href="#Fixed_in_Apache_Tomcat_8.5.24">Fixed 
in Apache Tomcat 8.5.24</a></li><li><a 
href="#Fixed_in_Apache_Tomcat_8.0.47">Fixed in Apache Tomcat 
8.0.47</a></li><li><a href="#Fixed_in_Apache_Tomcat_8.5.23">Fixed in Apache 
Tomcat 8.5.23</a></li><li><a href="#Fixed_in_Apache_Tomcat_8.0.45">Fixed in 
Apache Tomcat 8.0.45</a></li><li><a href="#Fixed_in_Apache_Tomcat_8.5.16">Fixed 
in Apache Tomcat 8.5.1
 6</a></li><li><a href="#Fixed_in_Apache_Tomcat_8.0.44">Fixed in Apache Tomcat 
8.0.44</a></li><li><a href="#Fixed_in_Apache_Tomcat_8.5.15">Fixed in Apache 
Tomcat 8.5.15</a></li><li><a href="#Fixed_in_Apache_Tomcat_8.0.43">Fixed in 
Apache Tomcat 8.0.43</a></li><li><a href="#Fixed_in_Apache_Tomcat_8.5.13">Fixed 
in Apache Tomcat 8.5.13</a></li><li><a 
href="#Fixed_in_Apache_Tomcat_8.0.42">Fixed in Apache Tomcat 
8.0.42</a></li><li><a href="#Fixed_in_Apache_Tomcat_8.5.12">Fixed in Apache 
Tomcat 8.5.12</a></li><li><a href="#Fixed_in_Apache_Tomcat_8.0.41">Fixed in 
Apache Tomcat 8.0.41</a></li><li><a href="#Fixed_in_Apache_Tomcat_8.5.11">Fixed 
in Apache Tomcat 8.5.11</a></li><li><a 
href="#Fixed_in_Apache_Tomcat_8.5.9">Fixed in Apache Tomcat 
8.5.9</a></li><li><a href="#Fixed_in_Apache_Tomcat_8.0.39">Fixed in Apache 
Tomcat 8.0.39</a></li><li><a href="#Fixed_in_Apache_Tomcat_8.5.8">Fixed in 
Apache Tomcat 8.5.8</a></li><li><a 
href="#Fixed_in_Apache_Tomcat_8.5.5_and_8.0.37">Fixed in Apache Tomcat 
 8.5.5 and 8.0.37</a></li><li><a 
href="#Fixed_in_Apache_Tomcat_8.5.3_and_8.0.36">Fixed in Apache Tomcat 8.5.3 
and 8.0.36</a></li><li><a href="#Fixed_in_Apache_Tomcat_8.0.32">Fixed in Apache 
Tomcat 8.0.32</a></li><li><a href="#Fixed_in_Apache_Tomcat_8.0.30">Fixed in 
Apache Tomcat 8.0.30</a></li><li><a href="#Fixed_in_Apache_Tomcat_8.0.27">Fixed 
in Apache Tomcat 8.0.27</a></li><li><a 
href="#Fixed_in_Apache_Tomcat_8.0.17">Fixed in Apache Tomcat 
8.0.17</a></li><li><a href="#Fixed_in_Apache_Tomcat_8.0.9">Fixed in Apache 
Tomcat 8.0.9</a></li><li><a href="#Fixed_in_Apache_Tomcat_8.0.8">Fixed in 
Apache Tomcat 8.0.8</a></li><li><a href="#Fixed_in_Apache_Tomcat_8.0.5">Fixed 
in Apache Tomcat 8.0.5</a></li><li><a 
href="#Fixed_in_Apache_Tomcat_8.0.3">Fixed in Apache Tomcat 
8.0.3</a></li><li><a href="#Fixed_in_Apache_Tomcat_8.0.0-RC10">Fixed in Apache 
Tomcat 8.0.0-RC10</a></li><li><a href="#Fixed_in_Apache_Tomcat_8.0.0-RC3">Fixed 
in Apache Tomcat 8.0.0-RC3</a></li><li><a href="#Not_a_vulnerability
 _in_Tomcat">Not a vulnerability in Tomcat</a></li></ul>
+<ul><li><a href="#Apache_Tomcat_8.x_vulnerabilities">Apache Tomcat 8.x 
vulnerabilities</a></li><li><a href="#Fixed_in_Apache_Tomcat_8.5.60">Fixed in 
Apache Tomcat 8.5.60</a></li><li><a href="#Fixed_in_Apache_Tomcat_8.5.58">Fixed 
in Apache Tomcat 8.5.58</a></li><li><a 
href="#Fixed_in_Apache_Tomcat_8.5.57">Fixed in Apache Tomcat 
8.5.57</a></li><li><a href="#Fixed_in_Apache_Tomcat_8.5.56">Fixed in Apache 
Tomcat 8.5.56</a></li><li><a href="#Fixed_in_Apache_Tomcat_8.5.55">Fixed in 
Apache Tomcat 8.5.55</a></li><li><a href="#Fixed_in_Apache_Tomcat_8.5.51">Fixed 
in Apache Tomcat 8.5.51</a></li><li><a 
href="#Fixed_in_Apache_Tomcat_8.5.50">Fixed in Apache Tomcat 
8.5.50</a></li><li><a href="#Fixed_in_Apache_Tomcat_8.5.49">Fixed in Apache 
Tomcat 8.5.49</a></li><li><a href="#Fixed_in_Apache_Tomcat_8.5.41">Fixed in 
Apache Tomcat 8.5.41</a></li><li><a href="#Fixed_in_Apache_Tomcat_8.5.40">Fixed 
in Apache Tomcat 8.5.40</a></li><li><a 
href="#Fixed_in_Apache_Tomcat_8.5.38">Fixed in Apache Tomcat 8.5.
 38</a></li><li><a href="#Fixed_in_Apache_Tomcat_8.5.34">Fixed in Apache Tomcat 
8.5.34</a></li><li><a href="#Fixed_in_Apache_Tomcat_8.0.53">Fixed in Apache 
Tomcat 8.0.53</a></li><li><a href="#Fixed_in_Apache_Tomcat_8.5.32">Fixed in 
Apache Tomcat 8.5.32</a></li><li><a href="#Fixed_in_Apache_Tomcat_8.0.52">Fixed 
in Apache Tomcat 8.0.52</a></li><li><a 
href="#Fixed_in_Apache_Tomcat_8.5.31">Fixed in Apache Tomcat 
8.5.31</a></li><li><a href="#Fixed_in_Apache_Tomcat_8.0.50">Fixed in Apache 
Tomcat 8.0.50</a></li><li><a href="#Fixed_in_Apache_Tomcat_8.5.28">Fixed in 
Apache Tomcat 8.5.28</a></li><li><a href="#Fixed_in_Apache_Tomcat_8.0.48">Fixed 
in Apache Tomcat 8.0.48</a></li><li><a 
href="#Fixed_in_Apache_Tomcat_8.5.24">Fixed in Apache Tomcat 
8.5.24</a></li><li><a href="#Fixed_in_Apache_Tomcat_8.0.47">Fixed in Apache 
Tomcat 8.0.47</a></li><li><a href="#Fixed_in_Apache_Tomcat_8.5.23">Fixed in 
Apache Tomcat 8.5.23</a></li><li><a href="#Fixed_in_Apache_Tomcat_8.0.45">Fixed 
in Apache Tomcat 8.0.4
 5</a></li><li><a href="#Fixed_in_Apache_Tomcat_8.5.16">Fixed in Apache Tomcat 
8.5.16</a></li><li><a href="#Fixed_in_Apache_Tomcat_8.0.44">Fixed in Apache 
Tomcat 8.0.44</a></li><li><a href="#Fixed_in_Apache_Tomcat_8.5.15">Fixed in 
Apache Tomcat 8.5.15</a></li><li><a href="#Fixed_in_Apache_Tomcat_8.0.43">Fixed 
in Apache Tomcat 8.0.43</a></li><li><a 
href="#Fixed_in_Apache_Tomcat_8.5.13">Fixed in Apache Tomcat 
8.5.13</a></li><li><a href="#Fixed_in_Apache_Tomcat_8.0.42">Fixed in Apache 
Tomcat 8.0.42</a></li><li><a href="#Fixed_in_Apache_Tomcat_8.5.12">Fixed in 
Apache Tomcat 8.5.12</a></li><li><a href="#Fixed_in_Apache_Tomcat_8.0.41">Fixed 
in Apache Tomcat 8.0.41</a></li><li><a 
href="#Fixed_in_Apache_Tomcat_8.5.11">Fixed in Apache Tomcat 
8.5.11</a></li><li><a href="#Fixed_in_Apache_Tomcat_8.5.9">Fixed in Apache 
Tomcat 8.5.9</a></li><li><a href="#Fixed_in_Apache_Tomcat_8.0.39">Fixed in 
Apache Tomcat 8.0.39</a></li><li><a href="#Fixed_in_Apache_Tomcat_8.5.8">Fixed 
in Apache Tomcat 8.5.8</a>
 </li><li><a href="#Fixed_in_Apache_Tomcat_8.5.5_and_8.0.37">Fixed in Apache 
Tomcat 8.5.5 and 8.0.37</a></li><li><a 
href="#Fixed_in_Apache_Tomcat_8.5.3_and_8.0.36">Fixed in Apache Tomcat 8.5.3 
and 8.0.36</a></li><li><a href="#Fixed_in_Apache_Tomcat_8.0.32">Fixed in Apache 
Tomcat 8.0.32</a></li><li><a href="#Fixed_in_Apache_Tomcat_8.0.30">Fixed in 
Apache Tomcat 8.0.30</a></li><li><a href="#Fixed_in_Apache_Tomcat_8.0.27">Fixed 
in Apache Tomcat 8.0.27</a></li><li><a 
href="#Fixed_in_Apache_Tomcat_8.0.17">Fixed in Apache Tomcat 
8.0.17</a></li><li><a href="#Fixed_in_Apache_Tomcat_8.0.9">Fixed in Apache 
Tomcat 8.0.9</a></li><li><a href="#Fixed_in_Apache_Tomcat_8.0.8">Fixed in 
Apache Tomcat 8.0.8</a></li><li><a href="#Fixed_in_Apache_Tomcat_8.0.5">Fixed 
in Apache Tomcat 8.0.5</a></li><li><a 
href="#Fixed_in_Apache_Tomcat_8.0.3">Fixed in Apache Tomcat 
8.0.3</a></li><li><a href="#Fixed_in_Apache_Tomcat_8.0.0-RC10">Fixed in Apache 
Tomcat 8.0.0-RC10</a></li><li><a href="#Fixed_in_Apache_Tomcat_8.
 0.0-RC3">Fixed in Apache Tomcat 8.0.0-RC3</a></li><li><a 
href="#Not_a_vulnerability_in_Tomcat">Not a vulnerability in 
Tomcat</a></li></ul>
 </div><h3 id="Apache_Tomcat_8.x_vulnerabilities">Apache Tomcat 8.x 
vulnerabilities</h3><div class="text">
     <p>This page lists all security vulnerabilities fixed in released versions
        of Apache Tomcat 8.x. Each vulnerability is given a
@@ -44,6 +44,27 @@
        <a href="security.html">Tomcat Security Team</a>. Thank you.
     </p>
 
+  </div><h3 id="Fixed_in_Apache_Tomcat_8.5.60"><span class="pull-right">17 
November 2020</span> Fixed in Apache Tomcat 8.5.60</h3><div class="text">
+
+    <p><strong>Moderate: HTTP/2 request header mix-up</strong>
+       <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-17527"; 
rel="nofollow">CVE-2020-17527</a></p>
+
+    <p>While investigating issue <a 
href="https://bz.apache.org/bugzilla/show_bug.cgi?id=64830";>64830</a> it was 
discovered that Apache
+       Tomcat could re-use an HTTP request header value from the previous 
stream
+       received on an HTTP/2 connection for the request associated with the
+       subsequent stream. While this would most likely lead to an error and the
+       closure of the HTTP/2 connection, it is possible that information could
+       leak between requests.
+    </p>
+
+    <p>This was fixed with commit
+       <a 
href="https://github.com/apache/tomcat/commit/21e3408671aac7e0d7e264e720cac8b1b189eb29";>21e34086</a>.</p>
+
+    <p>This issue was identified by the Apache Tomcat Security team on 10
+       November 2020. The issue was made public on 3 December 2020.</p>
+
+    <p>Affects: 8.5.0to 8.5.59</p>
+
   </div><h3 id="Fixed_in_Apache_Tomcat_8.5.58"><span class="pull-right">15 
September 2020</span> Fixed in Apache Tomcat 8.5.58</h3><div class="text">
 
     <p><strong>Moderate: HTTP/2 request mix-up</strong>

Modified: tomcat/site/trunk/docs/security-9.html
URL: 
http://svn.apache.org/viewvc/tomcat/site/trunk/docs/security-9.html?rev=1884073&r1=1884072&r2=1884073&view=diff
==============================================================================
--- tomcat/site/trunk/docs/security-9.html (original)
+++ tomcat/site/trunk/docs/security-9.html Thu Dec  3 18:01:08 2020
@@ -2,7 +2,7 @@
 <html lang="en"><head><META http-equiv="Content-Type" content="text/html; 
charset=UTF-8"><meta name="viewport" content="width=device-width, 
initial-scale=1"><link href="res/css/tomcat.css" rel="stylesheet" 
type="text/css"><link href="res/css/fonts/fonts.css" rel="stylesheet" 
type="text/css"><title>Apache Tomcat&reg; - Apache Tomcat 9 
vulnerabilities</title><meta name="author" content="Apache Tomcat 
Project"></head><body><div id="wrapper"><header id="header"><div 
class="clearfix"><div class="menu-toggler pull-left" tabindex="1"><div 
class="hamburger"></div></div><a href="http://tomcat.apache.org/";><img 
class="tomcat-logo pull-left noPrint" alt="Tomcat Home" 
src="res/images/tomcat.png"></a><h1 class="pull-left">Apache 
Tomcat<sup>&reg;</sup></h1><div class="asf-logos pull-right"><a 
href="https://www.apache.org/foundation/contributing.html"; target="_blank" 
class="pull-left"><img 
src="https://www.apache.org/images/SupportApache-small.png"; class="support-asf" 
alt="Support Apache"></a><a h
 ref="http://www.apache.org/"; target="_blank" class="pull-left"><img 
src="res/images/asf_logo.svg" class="asf-logo" alt="The Apache Software 
Foundation"></a></div></div></header><main id="middle"><div><div 
id="mainLeft"><div id="nav-wrapper"><form 
action="https://www.google.com/search"; method="get"><div 
class="searchbox"><input value="tomcat.apache.org" name="sitesearch" 
type="hidden"><input aria-label="Search text" placeholder="Search&hellip;" 
required="required" name="q" id="query" 
type="search"><button>GO</button></div></form><div class="asfevents"><a 
href="https://www.apache.org/events/current-event.html";><img 
src="https://www.apache.org/events/current-event-234x60.png"; alt="Next ASF 
event"><br>
               Save the date!
             </a></div><nav><div><h2>Apache Tomcat</h2><ul><li><a 
href="./index.html">Home</a></li><li><a 
href="./taglibs.html">Taglibs</a></li><li><a href="./maven-plugin.html">Maven 
Plugin</a></li></ul></div><div><h2>Download</h2><ul><li><a 
href="./whichversion.html">Which version?</a></li><li><a 
href="https://tomcat.apache.org/download-10.cgi";>Tomcat 10 
(alpha)</a></li><li><a href="https://tomcat.apache.org/download-90.cgi";>Tomcat 
9</a></li><li><a href="https://tomcat.apache.org/download-80.cgi";>Tomcat 
8</a></li><li><a href="https://tomcat.apache.org/download-70.cgi";>Tomcat 
7</a></li><li><a 
href="https://tomcat.apache.org/download-connectors.cgi";>Tomcat 
Connectors</a></li><li><a 
href="https://tomcat.apache.org/download-native.cgi";>Tomcat 
Native</a></li><li><a 
href="https://tomcat.apache.org/download-taglibs.cgi";>Taglibs</a></li><li><a 
href="https://archive.apache.org/dist/tomcat/";>Archives</a></li></ul></div><div><h2>Documentation</h2><ul><li><a
 href="./tomcat-10.0-doc/index.html"
 >Tomcat 10.0 (alpha)</a></li><li><a href="./tomcat-9.0-doc/index.html">Tomcat 
 >9.0</a></li><li><a href="./tomcat-8.5-doc/index.html">Tomcat 
 >8.5</a></li><li><a href="./tomcat-7.0-doc/index.html">Tomcat 
 >7.0</a></li><li><a href="./connectors-doc/">Tomcat Connectors</a></li><li><a 
 >href="./native-doc/">Tomcat Native</a></li><li><a 
 >href="https://cwiki.apache.org/confluence/display/TOMCAT";>Wiki</a></li><li><a 
 >href="./migration.html">Migration Guide</a></li><li><a 
 >href="./presentations.html">Presentations</a></li><li><a 
 >href="https://cwiki.apache.org/confluence/x/Bi8lBg";>Specifications</a></li></ul></div><div><h2>Problems?</h2><ul><li><a
 > href="./security.html">Security Reports</a></li><li><a 
 >href="./findhelp.html">Find help</a></li><li><a 
 >href="https://cwiki.apache.org/confluence/display/TOMCAT/FAQ";>FAQ</a></li><li><a
 > href="./lists.html">Mailing Lists</a></li><li><a href="./bugreport.html">Bug 
 >Database</a></li><li><a href="./irc.html">IRC</a></li></ul></div><div><h2>Get 
 >Involved</h2><ul><li>
 <a href="./getinvolved.html">Overview</a></li><li><a 
href="./source.html">Source code</a></li><li><a 
href="./ci.html">Buildbot</a></li><li><a 
href="https://cwiki.apache.org/confluence/x/vIPzBQ";>Translations</a></li><li><a 
href="./tools.html">Tools</a></li></ul></div><div><h2>Media</h2><ul><li><a 
href="https://twitter.com/theapachetomcat";>Twitter</a></li><li><a 
href="https://www.youtube.com/c/ApacheTomcatOfficial";>YouTube</a></li><li><a 
href="https://blogs.apache.org/tomcat/";>Blog</a></li></ul></div><div><h2>Misc</h2><ul><li><a
 href="./whoweare.html">Who We Are</a></li><li><a 
href="https://www.redbubble.com/people/comdev/works/30885254-apache-tomcat";>Swag</a></li><li><a
 href="./heritage.html">Heritage</a></li><li><a 
href="http://www.apache.org";>Apache Home</a></li><li><a 
href="./resources.html">Resources</a></li><li><a 
href="./contact.html">Contact</a></li><li><a 
href="./legal.html">Legal</a></li><li><a 
href="https://www.apache.org/foundation/contributing.html";>Support 
Apache</a></li
 ><li><a 
 >href="https://www.apache.org/foundation/sponsorship.html";>Sponsorship</a></li><li><a
 > href="http://www.apache.org/foundation/thanks.html";>Thanks</a></li><li><a 
 >href="http://www.apache.org/licenses/";>License</a></li></ul></div></nav></div></div><div
 > id="mainRight"><div id="content"><h2 style="display: none;">Content</h2><h3 
 >id="Table_of_Contents">Table of Contents</h3><div class="text">
-<ul><li><a href="#Apache_Tomcat_9.x_vulnerabilities">Apache Tomcat 9.x 
vulnerabilities</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.38">Fixed in 
Apache Tomcat 9.0.38</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.37">Fixed 
in Apache Tomcat 9.0.37</a></li><li><a 
href="#Fixed_in_Apache_Tomcat_9.0.36">Fixed in Apache Tomcat 
9.0.36</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.35">Fixed in Apache 
Tomcat 9.0.35</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.31">Fixed in 
Apache Tomcat 9.0.31</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.30">Fixed 
in Apache Tomcat 9.0.30</a></li><li><a 
href="#Fixed_in_Apache_Tomcat_9.0.29">Fixed in Apache Tomcat 
9.0.29</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.20">Fixed in Apache 
Tomcat 9.0.20</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.19">Fixed in 
Apache Tomcat 9.0.19</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.16">Fixed 
in Apache Tomcat 9.0.16</a></li><li><a 
href="#Fixed_in_Apache_Tomcat_9.0.12">Fixed in Apache Tomcat 9.0.
 12</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.10">Fixed in Apache Tomcat 
9.0.10</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.9">Fixed in Apache 
Tomcat 9.0.9</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.8">Fixed in 
Apache Tomcat 9.0.8</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.5">Fixed 
in Apache Tomcat 9.0.5</a></li><li><a 
href="#Fixed_in_Apache_Tomcat_9.0.2">Fixed in Apache Tomcat 
9.0.2</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.1">Fixed in Apache 
Tomcat 9.0.1</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.0.M22">Fixed in 
Apache Tomcat 9.0.0.M22</a></li><li><a 
href="#Fixed_in_Apache_Tomcat_9.0.0.M21">Fixed in Apache Tomcat 
9.0.0.M21</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.0.M19">Fixed in 
Apache Tomcat 9.0.0.M19</a></li><li><a 
href="#Fixed_in_Apache_Tomcat_9.0.0.M18">Fixed in Apache Tomcat 
9.0.0.M18</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.0.M17">Fixed in 
Apache Tomcat 9.0.0.M17</a></li><li><a 
href="#Fixed_in_Apache_Tomcat_9.0.0.M15">Fixed
  in Apache Tomcat 9.0.0.M15</a></li><li><a 
href="#Fixed_in_Apache_Tomcat_9.0.0.M13">Fixed in Apache Tomcat 
9.0.0.M13</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.0.M10">Fixed in 
Apache Tomcat 9.0.0.M10</a></li><li><a 
href="#Fixed_in_Apache_Tomcat_9.0.0.M8">Fixed in Apache Tomcat 
9.0.0.M8</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.0.M3">Fixed in Apache 
Tomcat 9.0.0.M3</a></li></ul>
+<ul><li><a href="#Apache_Tomcat_9.x_vulnerabilities">Apache Tomcat 9.x 
vulnerabilities</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.40">Fixed in 
Apache Tomcat 9.0.40</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.38">Fixed 
in Apache Tomcat 9.0.38</a></li><li><a 
href="#Fixed_in_Apache_Tomcat_9.0.37">Fixed in Apache Tomcat 
9.0.37</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.36">Fixed in Apache 
Tomcat 9.0.36</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.35">Fixed in 
Apache Tomcat 9.0.35</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.31">Fixed 
in Apache Tomcat 9.0.31</a></li><li><a 
href="#Fixed_in_Apache_Tomcat_9.0.30">Fixed in Apache Tomcat 
9.0.30</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.29">Fixed in Apache 
Tomcat 9.0.29</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.20">Fixed in 
Apache Tomcat 9.0.20</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.19">Fixed 
in Apache Tomcat 9.0.19</a></li><li><a 
href="#Fixed_in_Apache_Tomcat_9.0.16">Fixed in Apache Tomcat 9.0.
 16</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.12">Fixed in Apache Tomcat 
9.0.12</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.10">Fixed in Apache 
Tomcat 9.0.10</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.9">Fixed in 
Apache Tomcat 9.0.9</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.8">Fixed 
in Apache Tomcat 9.0.8</a></li><li><a 
href="#Fixed_in_Apache_Tomcat_9.0.5">Fixed in Apache Tomcat 
9.0.5</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.2">Fixed in Apache 
Tomcat 9.0.2</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.1">Fixed in 
Apache Tomcat 9.0.1</a></li><li><a 
href="#Fixed_in_Apache_Tomcat_9.0.0.M22">Fixed in Apache Tomcat 
9.0.0.M22</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.0.M21">Fixed in 
Apache Tomcat 9.0.0.M21</a></li><li><a 
href="#Fixed_in_Apache_Tomcat_9.0.0.M19">Fixed in Apache Tomcat 
9.0.0.M19</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.0.M18">Fixed in 
Apache Tomcat 9.0.0.M18</a></li><li><a 
href="#Fixed_in_Apache_Tomcat_9.0.0.M17">Fixed in Ap
 ache Tomcat 9.0.0.M17</a></li><li><a 
href="#Fixed_in_Apache_Tomcat_9.0.0.M15">Fixed in Apache Tomcat 
9.0.0.M15</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.0.M13">Fixed in 
Apache Tomcat 9.0.0.M13</a></li><li><a 
href="#Fixed_in_Apache_Tomcat_9.0.0.M10">Fixed in Apache Tomcat 
9.0.0.M10</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.0.M8">Fixed in 
Apache Tomcat 9.0.0.M8</a></li><li><a 
href="#Fixed_in_Apache_Tomcat_9.0.0.M3">Fixed in Apache Tomcat 
9.0.0.M3</a></li></ul>
 </div><h3 id="Apache_Tomcat_9.x_vulnerabilities">Apache Tomcat 9.x 
vulnerabilities</h3><div class="text">
     <p>This page lists all security vulnerabilities fixed in released versions
        of Apache Tomcat 9.x. Each vulnerability is given a
@@ -39,6 +39,27 @@
        <a href="security.html">Tomcat Security Team</a>. Thank you.
     </p>
 
+  </div><h3 id="Fixed_in_Apache_Tomcat_9.0.40"><span class="pull-right">17 
November 2020</span> Fixed in Apache Tomcat 9.0.40</h3><div class="text">
+
+    <p><strong>Moderate: HTTP/2 request header mix-up</strong>
+       <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-17527"; 
rel="nofollow">CVE-2020-17527</a></p>
+
+    <p>While investigating issue <a 
href="https://bz.apache.org/bugzilla/show_bug.cgi?id=64830";>64830</a> it was 
discovered that Apache
+       Tomcat could re-use an HTTP request header value from the previous 
stream
+       received on an HTTP/2 connection for the request associated with the
+       subsequent stream. While this would most likely lead to an error and the
+       closure of the HTTP/2 connection, it is possible that information could
+       leak between requests.
+    </p>
+
+    <p>This was fixed with commit
+       <a 
href="https://github.com/apache/tomcat/commit/d56293f816d6dc9e2b47107f208fa9e95db58c65";>d56293f8</a>.</p>
+
+    <p>This issue was identified by the Apache Tomcat Security team on 10
+       November 2020. The issue was made public on 3 December 2020.</p>
+
+    <p>Affects: 9.0.0-M1 to 9.0.39</p>
+
   </div><h3 id="Fixed_in_Apache_Tomcat_9.0.38"><span class="pull-right">15 
September 2020</span> Fixed in Apache Tomcat 9.0.38</h3><div class="text">
 
     <p><strong>Moderate: HTTP/2 request mix-up</strong>

Modified: tomcat/site/trunk/xdocs/security-10.xml
URL: 
http://svn.apache.org/viewvc/tomcat/site/trunk/xdocs/security-10.xml?rev=1884073&r1=1884072&r2=1884073&view=diff
==============================================================================
--- tomcat/site/trunk/xdocs/security-10.xml (original)
+++ tomcat/site/trunk/xdocs/security-10.xml Thu Dec  3 18:01:08 2020
@@ -50,6 +50,29 @@
 
   </section>
 
+  <section name="Fixed in Apache Tomcat 10.0.0-M10" rtext="17 November 2020">
+
+    <p><strong>Moderate: HTTP/2 request header mix-up</strong>
+       <cve>CVE-2020-17527</cve></p>
+
+    <p>While investigating issue <bug>64830</bug> it was discovered that Apache
+       Tomcat could re-use an HTTP request header value from the previous 
stream
+       received on an HTTP/2 connection for the request associated with the
+       subsequent stream. While this would most likely lead to an error and the
+       closure of the HTTP/2 connection, it is possible that information could
+       leak between requests.
+    </p>
+
+    <p>This was fixed with commit
+       <hashlink hash="8d2fe6894d6e258a6d615d7f786acca80e6020cb"/>.</p>
+
+    <p>This issue was identified by the Apache Tomcat Security team on 10
+       November 2020. The issue was made public on 3 December 2020.</p>
+
+    <p>Affects: 10.0.0-M1 to 10.0.0-M9</p>
+
+  </section>
+
   <section name="Fixed in Apache Tomcat 10.0.0-M8" rtext="14 September 2020">
 
     <p><strong>Moderate: HTTP/2 request mix-up</strong>

Modified: tomcat/site/trunk/xdocs/security-8.xml
URL: 
http://svn.apache.org/viewvc/tomcat/site/trunk/xdocs/security-8.xml?rev=1884073&r1=1884072&r2=1884073&view=diff
==============================================================================
--- tomcat/site/trunk/xdocs/security-8.xml (original)
+++ tomcat/site/trunk/xdocs/security-8.xml Thu Dec  3 18:01:08 2020
@@ -56,6 +56,29 @@
 
   </section>
 
+  <section name="Fixed in Apache Tomcat 8.5.60" rtext="17 November 2020">
+
+    <p><strong>Moderate: HTTP/2 request header mix-up</strong>
+       <cve>CVE-2020-17527</cve></p>
+
+    <p>While investigating issue <bug>64830</bug> it was discovered that Apache
+       Tomcat could re-use an HTTP request header value from the previous 
stream
+       received on an HTTP/2 connection for the request associated with the
+       subsequent stream. While this would most likely lead to an error and the
+       closure of the HTTP/2 connection, it is possible that information could
+       leak between requests.
+    </p>
+
+    <p>This was fixed with commit
+       <hashlink hash="21e3408671aac7e0d7e264e720cac8b1b189eb29"/>.</p>
+
+    <p>This issue was identified by the Apache Tomcat Security team on 10
+       November 2020. The issue was made public on 3 December 2020.</p>
+
+    <p>Affects: 8.5.0to 8.5.59</p>
+
+  </section>
+
   <section name="Fixed in Apache Tomcat 8.5.58" rtext="15 September 2020">
 
     <p><strong>Moderate: HTTP/2 request mix-up</strong>

Modified: tomcat/site/trunk/xdocs/security-9.xml
URL: 
http://svn.apache.org/viewvc/tomcat/site/trunk/xdocs/security-9.xml?rev=1884073&r1=1884072&r2=1884073&view=diff
==============================================================================
--- tomcat/site/trunk/xdocs/security-9.xml (original)
+++ tomcat/site/trunk/xdocs/security-9.xml Thu Dec  3 18:01:08 2020
@@ -50,6 +50,29 @@
 
   </section>
 
+  <section name="Fixed in Apache Tomcat 9.0.40" rtext="17 November 2020">
+
+    <p><strong>Moderate: HTTP/2 request header mix-up</strong>
+       <cve>CVE-2020-17527</cve></p>
+
+    <p>While investigating issue <bug>64830</bug> it was discovered that Apache
+       Tomcat could re-use an HTTP request header value from the previous 
stream
+       received on an HTTP/2 connection for the request associated with the
+       subsequent stream. While this would most likely lead to an error and the
+       closure of the HTTP/2 connection, it is possible that information could
+       leak between requests.
+    </p>
+
+    <p>This was fixed with commit
+       <hashlink hash="d56293f816d6dc9e2b47107f208fa9e95db58c65"/>.</p>
+
+    <p>This issue was identified by the Apache Tomcat Security team on 10
+       November 2020. The issue was made public on 3 December 2020.</p>
+
+    <p>Affects: 9.0.0-M1 to 9.0.39</p>
+
+  </section>
+
   <section name="Fixed in Apache Tomcat 9.0.38" rtext="15 September 2020">
 
     <p><strong>Moderate: HTTP/2 request mix-up</strong>



---------------------------------------------------------------------
To unsubscribe, e-mail: dev-unsubscr...@tomcat.apache.org
For additional commands, e-mail: dev-h...@tomcat.apache.org

Reply via email to