← Back

CVE-2022-45143

nvd nist
Published: Jan 3, 2023Modified: Jun 17, 2026

JSON object

Loading...
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Exploitability: 3.9 / Impact: 3.6
Source: NVD

Description

The JsonErrorReportValve in Apache Tomcat 8.5.83, 9.0.40 to 9.0.68 and 10.1.0-M1 to 10.1.1 did not escape the type, message or description values. In some circumstances these are constructed from user provided data and it was therefore possible for users to supply values that invalidated or manipulated the JSON output.

Affected (20)

Products: Apache: Tomcat
1 product
Tomcat
Configuration A
20 vulnerable
Vulnerable SoftwareAffected Versions
Apache
From 9.0.40 to 9.0.69
Version 10.1.0 milestone10
Version 10.1.0 milestone11
Version 10.1.0 milestone12
Version 10.1.0 milestone13
Version 10.1.0 milestone14
Version 10.1.0 milestone15
Version 10.1.0 milestone16
Version 10.1.0 milestone17
Version 10.1.0 milestone1
Version 10.1.0 milestone2
Version 10.1.0 milestone3
Version 10.1.0 milestone4
Version 10.1.0 milestone5
Version 10.1.0 milestone6
Version 10.1.0 milestone7
Version 10.1.0 milestone8
Version 10.1.0 milestone9
Version 10.1.1
Version 8.5.83

References (5)

Source: security@apache.org
Mailing ListVendor Advisory
Source: security@apache.org
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.