Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2022-45143

Опубликовано: 03 янв. 2023
Источник: debian
EPSS Низкий

Описание

The JsonErrorReportValve in Apache Tomcat 8.5.83, 9.0.40 to 9.0.68 and 10.1.0-M1 to 10.1.1 did not escape the type, message or description values. In some circumstances these are constructed from user provided data and it was therefore possible for users to supply values that invalidated or manipulated the JSON output.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
tomcat9fixed9.0.70-1package
tomcat9not-affectedbusterpackage
tomcat8removedpackage

Примечания

  • https://github.com/apache/tomcat/commit/b336f4e58893ea35114f1e4a415657f723b1298e (9.0.69)

  • https://github.com/apache/tomcat/commit/0cab3a56bd89f70e7481bb0d68395dc7e130dbbf (8.5.84)

  • https://www.openwall.com/lists/oss-security/2023/01/03/1

EPSS

Процентиль: 75%
0.00933
Низкий

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 2 лет назад

The JsonErrorReportValve in Apache Tomcat 8.5.83, 9.0.40 to 9.0.68 and 10.1.0-M1 to 10.1.1 did not escape the type, message or description values. In some circumstances these are constructed from user provided data and it was therefore possible for users to supply values that invalidated or manipulated the JSON output.

CVSS3: 7.5
redhat
больше 2 лет назад

The JsonErrorReportValve in Apache Tomcat 8.5.83, 9.0.40 to 9.0.68 and 10.1.0-M1 to 10.1.1 did not escape the type, message or description values. In some circumstances these are constructed from user provided data and it was therefore possible for users to supply values that invalidated or manipulated the JSON output.

CVSS3: 7.5
nvd
больше 2 лет назад

The JsonErrorReportValve in Apache Tomcat 8.5.83, 9.0.40 to 9.0.68 and 10.1.0-M1 to 10.1.1 did not escape the type, message or description values. In some circumstances these are constructed from user provided data and it was therefore possible for users to supply values that invalidated or manipulated the JSON output.

suse-cvrf
около 2 лет назад

Security update for tomcat

CVSS3: 7.5
github
больше 2 лет назад

Apache Tomcat improperly escapes input from JsonErrorReportValve

EPSS

Процентиль: 75%
0.00933
Низкий