VDB

DEBIAN-CVE-2022-45143

DEBIAN-CVE-2022-45143 PUBLISHED CVSS 7.5 HIGH

The JsonErrorReportValve in Apache Tomcat 8.5.83, 9.0.40 to 9.0.68 and 10.1.0-M1 to 10.1.1 did not escape the type, message or description values. In some circumstances these are constructed from user provided data and it was therefore possible for users to supply values that invalidated or manipulated the JSON output.

Risk Scores

CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Affected Products

VendorProductVersions
Debian:14tomcat90, 0, 0
Debian:11tomcat99.0.43-2, 9.0.43-2, 9.0.43-2
Debian:12tomcat90, 0, 0
Debian:13tomcat90, 0, 0

Timeline

  • Jan 3, 2023 CVE Published
  • Apr 28, 2026 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›