CVE-2022-45143

The JsonErrorReportValve in Apache Tomcat 8.5.83, 9.0.40 to 9.0.68 and 10.1.0-M1 to 10.1.1 did not escape the type, message or description values. In some circumstances these are constructed from user provided data and it was therefore possible for users to supply values that invalidated or manipulated the JSON output.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
apacheCNA
---
---
CVEADP
---
---
CISA-ADPADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 73%
VendorProductVersion
apachetomcat
9.0.40 ≤
𝑥
< 9.0.69
apachetomcat
8.5.83
apachetomcat
10.1.0:milestone1
apachetomcat
10.1.0:milestone10
apachetomcat
10.1.0:milestone11
apachetomcat
10.1.0:milestone12
apachetomcat
10.1.0:milestone13
apachetomcat
10.1.0:milestone14
apachetomcat
10.1.0:milestone15
apachetomcat
10.1.0:milestone16
apachetomcat
10.1.0:milestone17
apachetomcat
10.1.0:milestone2
apachetomcat
10.1.0:milestone3
apachetomcat
10.1.0:milestone4
apachetomcat
10.1.0:milestone5
apachetomcat
10.1.0:milestone6
apachetomcat
10.1.0:milestone7
apachetomcat
10.1.0:milestone8
apachetomcat
10.1.0:milestone9
apachetomcat
10.1.1
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
tomcat9
bullseye (security)
9.0.43-2~deb11u10
fixed
bullseye
9.0.43-2~deb11u10
fixed
buster
not-affected
bookworm
9.0.70-2
fixed
sid
9.0.95-1
fixed
trixie
9.0.95-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
tomcat8
kinetic
dne
jammy
dne
focal
dne
bionic
needs-triage
xenial
needs-triage
trusty
ignored
tomcat9
noble
not-affected
mantic
not-affected
lunar
not-affected
kinetic
ignored
jammy
needs-triage
focal
needs-triage
bionic
needs-triage
xenial
ignored
trusty
ignored