CVE-2022-25762
Response mix-up with WebSocket concurrent send and close
8.6
HIGH
CVSS 3.1
EPSS 8.0%
描述
If a web application sends a WebSocket message concurrently with the WebSocket connection closing when running on Apache Tomcat 8.5.0 to 8.5.75 or Apache Tomcat 9.0.0 to 9.0.20, it is possible that the application will continue to use the socket after it has been closed. The error handling triggered in this case could cause the a pooled object to be placed in the pool twice. This could result in subsequent connections using the same object concurrently which could result in data being returned to the wrong use and/or other errors.
如何修補 CVE-2022-25762
要修補 CVE-2022-25762,請將受影響套件升級到下列已修補版本。
- —升級至 8.5.76 或更新版本
- —升級至 9.0.22-1 或更新版本
- —升級至 8.5.75 或更新版本
CVE-2022-25762 正在被利用嗎?
中等 — EPSS 為 8.0%,可持續追蹤但非最高優先。
受影響套件(3)
- >= 8.5.0, < 8.5.76, >= 9.0.0, < 9.0.21
- from 0, < 9.0.22-1
- >= 8.5.0, < 8.5.75
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH8.6 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L |