The JsonErrorReportValve in Apache Tomcat 8.5.83, 9.0.40 to 9.0.68 and 10.1.0-M1 to 10.1.1 did not escape the type, message or description values. In some circumstances these are constructed from user provided data and it was therefore possible for users to supply values that invalidated or manipulated the JSON output.
Advisories
Source ID Title
Debian DSA Debian DSA DSA-5381-1 tomcat9 security update
EUVD EUVD EUVD-2023-0546 The JsonErrorReportValve in Apache Tomcat 8.5.83, 9.0.40 to 9.0.68 and 10.1.0-M1 to 10.1.1 did not escape the type, message or description values. In some circumstances these are constructed from user provided data and it was therefore possible for users to supply values that invalidated or manipulated the JSON output.
Github GHSA Github GHSA GHSA-rq2w-37h9-vg94 Apache Tomcat improperly escapes input from JsonErrorReportValve
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2024-08-03T14:09:56.475Z

Reserved: 2022-11-10T15:00:33.203Z

Link: CVE-2022-45143

cve-icon Vulnrichment

Updated: 2024-08-03T14:09:56.475Z

cve-icon NVD

Status : Modified

Published: 2023-01-03T19:15:10.403

Modified: 2024-11-21T07:28:50.497

Link: CVE-2022-45143

cve-icon Redhat

Severity : Low

Publid Date: 2023-01-03T00:00:00Z

Links: CVE-2022-45143 - Bugzilla

cve-icon OpenCVE Enrichment

No data.