Lucene search

K
githubGitHub Advisory DatabaseGHSA-RQ2W-37H9-VG94
HistoryJan 03, 2023 - 9:30 p.m.

Apache Tomcat improperly escapes input from JsonErrorReportValve

2023-01-0321:30:21
CWE-74
CWE-116
GitHub Advisory Database
github.com
50
apache tomcat
jsonerrorreportvalve
input security
json manipulation
software vulnerability

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

EPSS

0.003

Percentile

71.6%

The JsonErrorReportValve in Apache Tomcat 8.5.83, 9.0.40 to 9.0.68 and 10.1.0-M1 to 10.1.1 does not escape the type, message or description values. In some circumstances these are constructed from user provided data and it was therefore possible for users to supply values that invalidated or manipulated the JSON output.

Affected configurations

Vulners
Node
org.apache.tomcattomcat-utilRange9.0.409.0.69
OR
org.apache.tomcattomcat-utilMatch8.5.83
OR
org.apache.tomcattomcat-catalinaRange10.1.010.1.1
OR
org.apache.tomcat.embedtomcat-embed-coreRange10.1.010.1.1
OR
org.apache.tomcat.embedtomcat-embed-coreRange9.0.409.0.68
OR
org.apache.tomcat.embedtomcat-embed-coreMatch8.5.83
VendorProductVersionCPE
org.apache.tomcattomcat-util*cpe:2.3:a:org.apache.tomcat:tomcat-util:*:*:*:*:*:*:*:*
org.apache.tomcattomcat-util8.5.83cpe:2.3:a:org.apache.tomcat:tomcat-util:8.5.83:*:*:*:*:*:*:*
org.apache.tomcattomcat-catalina*cpe:2.3:a:org.apache.tomcat:tomcat-catalina:*:*:*:*:*:*:*:*
org.apache.tomcat.embedtomcat-embed-core*cpe:2.3:a:org.apache.tomcat.embed:tomcat-embed-core:*:*:*:*:*:*:*:*
org.apache.tomcat.embedtomcat-embed-core8.5.83cpe:2.3:a:org.apache.tomcat.embed:tomcat-embed-core:8.5.83:*:*:*:*:*:*:*

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

EPSS

0.003

Percentile

71.6%