Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2022-45143

Опубликовано: 03 янв. 2023
Источник: debian
EPSS Низкий

Описание

The JsonErrorReportValve in Apache Tomcat 8.5.83, 9.0.40 to 9.0.68 and 10.1.0-M1 to 10.1.1 did not escape the type, message or description values. In some circumstances these are constructed from user provided data and it was therefore possible for users to supply values that invalidated or manipulated the JSON output.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
tomcat9fixed9.0.70-1package
tomcat9not-affectedbusterpackage
tomcat8removedpackage

Примечания

  • https://github.com/apache/tomcat/commit/b336f4e58893ea35114f1e4a415657f723b1298e (9.0.69)

  • https://github.com/apache/tomcat/commit/0cab3a56bd89f70e7481bb0d68395dc7e130dbbf (8.5.84)

  • https://www.openwall.com/lists/oss-security/2023/01/03/1

EPSS

Процентиль: 76%
0.0095
Низкий

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 3 лет назад

The JsonErrorReportValve in Apache Tomcat 8.5.83, 9.0.40 to 9.0.68 and 10.1.0-M1 to 10.1.1 did not escape the type, message or description values. In some circumstances these are constructed from user provided data and it was therefore possible for users to supply values that invalidated or manipulated the JSON output.

CVSS3: 7.5
redhat
около 3 лет назад

The JsonErrorReportValve in Apache Tomcat 8.5.83, 9.0.40 to 9.0.68 and 10.1.0-M1 to 10.1.1 did not escape the type, message or description values. In some circumstances these are constructed from user provided data and it was therefore possible for users to supply values that invalidated or manipulated the JSON output.

CVSS3: 7.5
nvd
около 3 лет назад

The JsonErrorReportValve in Apache Tomcat 8.5.83, 9.0.40 to 9.0.68 and 10.1.0-M1 to 10.1.1 did not escape the type, message or description values. In some circumstances these are constructed from user provided data and it was therefore possible for users to supply values that invalidated or manipulated the JSON output.

suse-cvrf
почти 3 года назад

Security update for tomcat

CVSS3: 7.5
github
около 3 лет назад

Apache Tomcat improperly escapes input from JsonErrorReportValve

EPSS

Процентиль: 76%
0.0095
Низкий