Tomcat — контейнер сервлетов с открытым исходным кодом
Релизный цикл, информация об уязвимостях
График релизов
Количество 1 466
GHSA-rq2w-37h9-vg94
Apache Tomcat improperly escapes input from JsonErrorReportValve
CVE-2022-45143
The JsonErrorReportValve in Apache Tomcat 8.5.83, 9.0.40 to 9.0.68 and 10.1.0-M1 to 10.1.1 did not escape the type, message or description values. In some circumstances these are constructed from user provided data and it was therefore possible for users to supply values that invalidated or manipulated the JSON output.
CVE-2022-45143
The JsonErrorReportValve in Apache Tomcat 8.5.83, 9.0.40 to 9.0.68 and ...
CVE-2022-45143
The JsonErrorReportValve in Apache Tomcat 8.5.83, 9.0.40 to 9.0.68 and 10.1.0-M1 to 10.1.1 did not escape the type, message or description values. In some circumstances these are constructed from user provided data and it was therefore possible for users to supply values that invalidated or manipulated the JSON output.
CVE-2022-45143
The JsonErrorReportValve in Apache Tomcat 8.5.83, 9.0.40 to 9.0.68 and 10.1.0-M1 to 10.1.1 did not escape the type, message or description values. In some circumstances these are constructed from user provided data and it was therefore possible for users to supply values that invalidated or manipulated the JSON output.
SUSE-SU-2022:4303-1
Security update for tomcat
SUSE-SU-2022:4193-1
Security update for tomcat
SUSE-SU-2022:4009-1
Security update for tomcat
BDU:2024-03597
Уязвимость класса JsonErrorReportValve сервера приложений Apache Tomcat, позволяющая нарушителю оказать влияние на целостность защищаемой информации
GHSA-p22x-g9px-3945
Apache Tomcat may reject request containing invalid Content-Length header
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
GHSA-rq2w-37h9-vg94 Apache Tomcat improperly escapes input from JsonErrorReportValve | CVSS3: 7.5 | 3% Низкий | больше 3 лет назад | |
CVE-2022-45143 The JsonErrorReportValve in Apache Tomcat 8.5.83, 9.0.40 to 9.0.68 and 10.1.0-M1 to 10.1.1 did not escape the type, message or description values. In some circumstances these are constructed from user provided data and it was therefore possible for users to supply values that invalidated or manipulated the JSON output. | CVSS3: 7.5 | 3% Низкий | больше 3 лет назад | |
CVE-2022-45143 The JsonErrorReportValve in Apache Tomcat 8.5.83, 9.0.40 to 9.0.68 and ... | CVSS3: 7.5 | 3% Низкий | больше 3 лет назад | |
CVE-2022-45143 The JsonErrorReportValve in Apache Tomcat 8.5.83, 9.0.40 to 9.0.68 and 10.1.0-M1 to 10.1.1 did not escape the type, message or description values. In some circumstances these are constructed from user provided data and it was therefore possible for users to supply values that invalidated or manipulated the JSON output. | CVSS3: 7.5 | 3% Низкий | больше 3 лет назад | |
CVE-2022-45143 The JsonErrorReportValve in Apache Tomcat 8.5.83, 9.0.40 to 9.0.68 and 10.1.0-M1 to 10.1.1 did not escape the type, message or description values. In some circumstances these are constructed from user provided data and it was therefore possible for users to supply values that invalidated or manipulated the JSON output. | CVSS3: 7.5 | 3% Низкий | больше 3 лет назад | |
SUSE-SU-2022:4303-1 Security update for tomcat | 1% Низкий | больше 3 лет назад | ||
SUSE-SU-2022:4193-1 Security update for tomcat | 1% Низкий | больше 3 лет назад | ||
SUSE-SU-2022:4009-1 Security update for tomcat | 2% Низкий | больше 3 лет назад | ||
BDU:2024-03597 Уязвимость класса JsonErrorReportValve сервера приложений Apache Tomcat, позволяющая нарушителю оказать влияние на целостность защищаемой информации | CVSS3: 7.5 | 3% Низкий | больше 3 лет назад | |
GHSA-p22x-g9px-3945 Apache Tomcat may reject request containing invalid Content-Length header | CVSS3: 7.5 | 1% Низкий | почти 4 года назад |
Уязвимостей на страницу