Логотип exploitDog
product: "tomcat"
Консоль
Логотип exploitDog

exploitDog

product: "tomcat"
Tomcat

Tomcatконтейнер сервлетов с открытым исходным кодом

Релизный цикл, информация об уязвимостях

Продукт: Tomcat
Вендор: apache

График релизов

8.08.5910.010.111.02014201520162017201820192020202120222023202420252026

Недавние уязвимости Tomcat

Количество 1 243

nvd логотип

CVE-2022-45143

почти 3 года назад

The JsonErrorReportValve in Apache Tomcat 8.5.83, 9.0.40 to 9.0.68 and 10.1.0-M1 to 10.1.1 did not escape the type, message or description values. In some circumstances these are constructed from user provided data and it was therefore possible for users to supply values that invalidated or manipulated the JSON output.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2022-45143

почти 3 года назад

The JsonErrorReportValve in Apache Tomcat 8.5.83, 9.0.40 to 9.0.68 and ...

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2022-45143

почти 3 года назад

The JsonErrorReportValve in Apache Tomcat 8.5.83, 9.0.40 to 9.0.68 and 10.1.0-M1 to 10.1.1 did not escape the type, message or description values. In some circumstances these are constructed from user provided data and it was therefore possible for users to supply values that invalidated or manipulated the JSON output.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2022-45143

почти 3 года назад

The JsonErrorReportValve in Apache Tomcat 8.5.83, 9.0.40 to 9.0.68 and 10.1.0-M1 to 10.1.1 did not escape the type, message or description values. In some circumstances these are constructed from user provided data and it was therefore possible for users to supply values that invalidated or manipulated the JSON output.

CVSS3: 7.5
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2022:4303-1

почти 3 года назад

Security update for tomcat

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2022:4193-1

почти 3 года назад

Security update for tomcat

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2022:4009-1

почти 3 года назад

Security update for tomcat

EPSS: Низкий
fstec логотип

BDU:2024-03597

почти 3 года назад

Уязвимость класса JsonErrorReportValve сервера приложений Apache Tomcat, позволяющая нарушителю оказать влияние на целостность защищаемой информации

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-p22x-g9px-3945

около 3 лет назад

Apache Tomcat may reject request containing invalid Content-Length header

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2022-42252

около 3 лет назад

If Apache Tomcat 8.5.0 to 8.5.82, 9.0.0-M1 to 9.0.67, 10.0.0-M1 to 10.0.26 or 10.1.0-M1 to 10.1.0 was configured to ignore invalid HTTP headers via setting rejectIllegalHeader to false (the default for 8.5.x only), Tomcat did not reject a request containing an invalid Content-Length header making a request smuggling attack possible if Tomcat was located behind a reverse proxy that also failed to reject the request with the invalid header.

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
nvd логотип
CVE-2022-45143

The JsonErrorReportValve in Apache Tomcat 8.5.83, 9.0.40 to 9.0.68 and 10.1.0-M1 to 10.1.1 did not escape the type, message or description values. In some circumstances these are constructed from user provided data and it was therefore possible for users to supply values that invalidated or manipulated the JSON output.

CVSS3: 7.5
1%
Низкий
почти 3 года назад
debian логотип
CVE-2022-45143

The JsonErrorReportValve in Apache Tomcat 8.5.83, 9.0.40 to 9.0.68 and ...

CVSS3: 7.5
1%
Низкий
почти 3 года назад
ubuntu логотип
CVE-2022-45143

The JsonErrorReportValve in Apache Tomcat 8.5.83, 9.0.40 to 9.0.68 and 10.1.0-M1 to 10.1.1 did not escape the type, message or description values. In some circumstances these are constructed from user provided data and it was therefore possible for users to supply values that invalidated or manipulated the JSON output.

CVSS3: 7.5
1%
Низкий
почти 3 года назад
redhat логотип
CVE-2022-45143

The JsonErrorReportValve in Apache Tomcat 8.5.83, 9.0.40 to 9.0.68 and 10.1.0-M1 to 10.1.1 did not escape the type, message or description values. In some circumstances these are constructed from user provided data and it was therefore possible for users to supply values that invalidated or manipulated the JSON output.

CVSS3: 7.5
1%
Низкий
почти 3 года назад
suse-cvrf логотип
SUSE-SU-2022:4303-1

Security update for tomcat

0%
Низкий
почти 3 года назад
suse-cvrf логотип
SUSE-SU-2022:4193-1

Security update for tomcat

0%
Низкий
почти 3 года назад
suse-cvrf логотип
SUSE-SU-2022:4009-1

Security update for tomcat

0%
Низкий
почти 3 года назад
fstec логотип
BDU:2024-03597

Уязвимость класса JsonErrorReportValve сервера приложений Apache Tomcat, позволяющая нарушителю оказать влияние на целостность защищаемой информации

CVSS3: 7.5
1%
Низкий
почти 3 года назад
github логотип
GHSA-p22x-g9px-3945

Apache Tomcat may reject request containing invalid Content-Length header

CVSS3: 7.5
0%
Низкий
около 3 лет назад
nvd логотип
CVE-2022-42252

If Apache Tomcat 8.5.0 to 8.5.82, 9.0.0-M1 to 9.0.67, 10.0.0-M1 to 10.0.26 or 10.1.0-M1 to 10.1.0 was configured to ignore invalid HTTP headers via setting rejectIllegalHeader to false (the default for 8.5.x only), Tomcat did not reject a request containing an invalid Content-Length header making a request smuggling attack possible if Tomcat was located behind a reverse proxy that also failed to reject the request with the invalid header.

CVSS3: 7.5
0%
Низкий
около 3 лет назад

Уязвимостей на страницу


Поделиться