CVE-2020-17527: Information Exposure
(updated )
While investigating bug it was discovered that Apache Tomcat to to to could re-use an HTTP request header value from the previous stream received on an HTTP/2
connection for the request associated with the subsequent stream. While this would most likely lead to an error and the closure of the HTTP/2
connection, it is possible that information could leak between requests.
References
Detect and mitigate CVE-2020-17527 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →