CVE-2022-34305
23.06.2022, 11:15
In Apache Tomcat 10.1.0-M1 to 10.1.0-M16, 10.0.0-M1 to 10.0.22, 9.0.30 to 9.0.64 and 8.5.50 to 8.5.81 the Form authentication example in the examples web application displayed user provided data without filtering, exposing a XSS vulnerability.
| Vendor | Product | Version |
|---|---|---|
| apache | tomcat | 8.5.50 ≤ 𝑥 ≤ 8.5.81 |
| apache | tomcat | 9.0.30 ≤ 𝑥 ≤ 9.0.64 |
| apache | tomcat | 10.0.0 ≤ 𝑥 ≤ 10.0.22 |
| apache | tomcat | 10.1.0:milestone1 |
| apache | tomcat | 10.1.0:milestone10 |
| apache | tomcat | 10.1.0:milestone11 |
| apache | tomcat | 10.1.0:milestone12 |
| apache | tomcat | 10.1.0:milestone13 |
| apache | tomcat | 10.1.0:milestone14 |
| apache | tomcat | 10.1.0:milestone15 |
| apache | tomcat | 10.1.0:milestone16 |
| apache | tomcat | 10.1.0:milestone2 |
| apache | tomcat | 10.1.0:milestone3 |
| apache | tomcat | 10.1.0:milestone4 |
| apache | tomcat | 10.1.0:milestone5 |
| apache | tomcat | 10.1.0:milestone6 |
| apache | tomcat | 10.1.0:milestone7 |
| apache | tomcat | 10.1.0:milestone8 |
| apache | tomcat | 10.1.0:milestone9 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| tomcat6 |
| ||||||||||||||||||||
| tomcat7 |
| ||||||||||||||||||||
| tomcat8 |
| ||||||||||||||||||||
| tomcat9 |
|
References