Lucene search

K
f5F5F5:K000133390
HistoryApr 18, 2023 - 12:00 a.m.

K000133390 : Apache Tomcat vulnerability CVE-2022-45143

2023-04-1800:00:00
my.f5.com
11
apache tomcat
cve-2022-45143
vulnerability
json
crafting
invalid
data

AI Score

6.4

Confidence

Low

EPSS

0.003

Percentile

71.6%

Security Advisory Description

The JsonErrorReportValve in Apache Tomcat 8.5.83, 9.0.40 to 9.0.68 and 10.1.0-M1 to 10.1.1 did not escape the type, message or description values. In some circumstances these are constructed from user provided data and it was therefore possible for users to supply values that invalidated or manipulated the JSON output. (CVE-2022-45143)

Impact

A user may be able to exploit this vulnerability by crafting invalid JSON data, causing an undesirable result.