Description
The JsonErrorReportValve in Apache Tomcat 8.5.83, 9.0.40 to 9.0.68 and 10.1.0-M1 to 10.1.1 did not escape the type, message or description values. In some circumstances these are constructed from user provided data and it was therefore possible for users to supply values that invalidated or manipulated the JSON output.
Published: 2023-01-03
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-5381-1 tomcat9 security update
EUVD EUVD EUVD-2023-0546 The JsonErrorReportValve in Apache Tomcat 8.5.83, 9.0.40 to 9.0.68 and 10.1.0-M1 to 10.1.1 did not escape the type, message or description values. In some circumstances these are constructed from user provided data and it was therefore possible for users to supply values that invalidated or manipulated the JSON output.
Github GHSA Github GHSA GHSA-rq2w-37h9-vg94 Apache Tomcat improperly escapes input from JsonErrorReportValve
History

No history.

Subscriptions

Apache Tomcat
Redhat Jboss Enterprise Web Server Jboss Fuse Openshift Application Runtimes
cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2024-08-03T14:09:56.475Z

Reserved: 2022-11-10T15:00:33.203Z

Link: CVE-2022-45143

cve-icon Vulnrichment

Updated: 2024-08-03T14:09:56.475Z

cve-icon NVD

Status : Modified

Published: 2023-01-03T19:15:10.403

Modified: 2024-11-21T07:28:50.497

Link: CVE-2022-45143

cve-icon Redhat

Severity : Low

Publid Date: 2023-01-03T00:00:00Z

Links: CVE-2022-45143 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses