CVE-2022-34305

NameCVE-2022-34305
DescriptionIn Apache Tomcat 10.1.0-M1 to 10.1.0-M16, 10.0.0-M1 to 10.0.22, 9.0.30 to 9.0.64 and 8.5.50 to 8.5.81 the Form authentication example in the examples web application displayed user provided data without filtering, exposing a XSS vulnerability.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, Mageia, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
tomcat9 (PTS)buster, buster (security)9.0.31-1~deb10u6vulnerable
bullseye (security), bullseye9.0.43-2~deb11u3vulnerable
bookworm, sid9.0.64-2vulnerable

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
tomcat8source(unstable)(unfixed)unimportant
tomcat9source(unstable)(unfixed)unimportant

Notes

https://lists.apache.org/thread/k04zk0nq6w57m72w5gb0r6z9ryhmvr4k
https://github.com/apache/tomcat/commit/8b60af90b99945379c2d1003277e0cabc6776bac (9.0.65)
https://github.com/apache/tomcat/commit/5f6c88b054b0e4fbccff8b7f15974ed55d59a9f7 (8.5.82)
Only an issue in the Form authentication example from the examples web application

Search for package or bug name: Reporting problems