Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Tomcat

Tomcatконтейнер сервлетов с открытым исходным кодом

Релизный цикл, информация об уязвимостях

Продукт: Tomcat
Вендор: apache

График релизов

9.010.010.111.0201720182019202020212022202320242025202620272028

Недавние уязвимости Tomcat

Количество 1 466

github логотип

GHSA-rq2w-37h9-vg94

больше 3 лет назад

Apache Tomcat improperly escapes input from JsonErrorReportValve

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2022-45143

больше 3 лет назад

The JsonErrorReportValve in Apache Tomcat 8.5.83, 9.0.40 to 9.0.68 and 10.1.0-M1 to 10.1.1 did not escape the type, message or description values. In some circumstances these are constructed from user provided data and it was therefore possible for users to supply values that invalidated or manipulated the JSON output.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2022-45143

больше 3 лет назад

The JsonErrorReportValve in Apache Tomcat 8.5.83, 9.0.40 to 9.0.68 and ...

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2022-45143

больше 3 лет назад

The JsonErrorReportValve in Apache Tomcat 8.5.83, 9.0.40 to 9.0.68 and 10.1.0-M1 to 10.1.1 did not escape the type, message or description values. In some circumstances these are constructed from user provided data and it was therefore possible for users to supply values that invalidated or manipulated the JSON output.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2022-45143

больше 3 лет назад

The JsonErrorReportValve in Apache Tomcat 8.5.83, 9.0.40 to 9.0.68 and 10.1.0-M1 to 10.1.1 did not escape the type, message or description values. In some circumstances these are constructed from user provided data and it was therefore possible for users to supply values that invalidated or manipulated the JSON output.

CVSS3: 7.5
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2022:4303-1

больше 3 лет назад

Security update for tomcat

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2022:4193-1

больше 3 лет назад

Security update for tomcat

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2022:4009-1

больше 3 лет назад

Security update for tomcat

EPSS: Низкий
fstec логотип

BDU:2024-03597

больше 3 лет назад

Уязвимость класса JsonErrorReportValve сервера приложений Apache Tomcat, позволяющая нарушителю оказать влияние на целостность защищаемой информации

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-p22x-g9px-3945

почти 4 года назад

Apache Tomcat may reject request containing invalid Content-Length header

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
github логотип
GHSA-rq2w-37h9-vg94

Apache Tomcat improperly escapes input from JsonErrorReportValve

CVSS3: 7.5
3%
Низкий
больше 3 лет назад
nvd логотип
CVE-2022-45143

The JsonErrorReportValve in Apache Tomcat 8.5.83, 9.0.40 to 9.0.68 and 10.1.0-M1 to 10.1.1 did not escape the type, message or description values. In some circumstances these are constructed from user provided data and it was therefore possible for users to supply values that invalidated or manipulated the JSON output.

CVSS3: 7.5
3%
Низкий
больше 3 лет назад
debian логотип
CVE-2022-45143

The JsonErrorReportValve in Apache Tomcat 8.5.83, 9.0.40 to 9.0.68 and ...

CVSS3: 7.5
3%
Низкий
больше 3 лет назад
ubuntu логотип
CVE-2022-45143

The JsonErrorReportValve in Apache Tomcat 8.5.83, 9.0.40 to 9.0.68 and 10.1.0-M1 to 10.1.1 did not escape the type, message or description values. In some circumstances these are constructed from user provided data and it was therefore possible for users to supply values that invalidated or manipulated the JSON output.

CVSS3: 7.5
3%
Низкий
больше 3 лет назад
redhat логотип
CVE-2022-45143

The JsonErrorReportValve in Apache Tomcat 8.5.83, 9.0.40 to 9.0.68 and 10.1.0-M1 to 10.1.1 did not escape the type, message or description values. In some circumstances these are constructed from user provided data and it was therefore possible for users to supply values that invalidated or manipulated the JSON output.

CVSS3: 7.5
3%
Низкий
больше 3 лет назад
suse-cvrf логотип
SUSE-SU-2022:4303-1

Security update for tomcat

1%
Низкий
больше 3 лет назад
suse-cvrf логотип
SUSE-SU-2022:4193-1

Security update for tomcat

1%
Низкий
больше 3 лет назад
suse-cvrf логотип
SUSE-SU-2022:4009-1

Security update for tomcat

2%
Низкий
больше 3 лет назад
fstec логотип
BDU:2024-03597

Уязвимость класса JsonErrorReportValve сервера приложений Apache Tomcat, позволяющая нарушителю оказать влияние на целостность защищаемой информации

CVSS3: 7.5
3%
Низкий
больше 3 лет назад
github логотип
GHSA-p22x-g9px-3945

Apache Tomcat may reject request containing invalid Content-Length header

CVSS3: 7.5
1%
Низкий
почти 4 года назад

Уязвимостей на страницу


Поделиться