CVE-2018-8037 is a race condition vulnerability in Apache Tomcat versions 9.0.0.M9 to 9.0.9 and 8.5.5 to 8.5.31. This flaw could lead to information disclosure, where a user might receive a response intended for another user due to simultaneous async request completion and container timeout. Rated as Medium severity (CVSS 5.9), it has a network attack vector and high attack complexity, with potential for high confidentiality impact. There is no evidence of active exploitation, public exploit code, or Metasploit/Nuclei modules, and community discussion is minimal, though it has received some media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 8.5.5, <= 8.5.31CPE matchmatch criteria | cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:* | ||
>= 9.0.1, <= 9.0.9CPE matchmatch criteria | cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:* | ||
9.0.0CPE matchmatch criteria | cpe:2.3:a:apache:tomcat:9.0.0:*:*:*:*:*:*:* | ||
9.0.0CPE matchmatch criteria | cpe:2.3:a:apache:tomcat:9.0.0:milestone10:*:*:*:*:*:* | ||
9.0.0CPE matchmatch criteria | cpe:2.3:a:apache:tomcat:9.0.0:milestone11:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.