Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2022-45143
Description:The JsonErrorReportValve in Apache Tomcat 8.5.83, 9.0.40 to 9.0.68 and 10.1.0-M1 to 10.1.1 did not escape the type, message or description values. In some circumstances these are constructed from user provided data and it was therefore possible for users to supply values that invalidated or manipulated the JSON output.
Test IDs: 1.3.6.1.4.1.25623.1.1.4.2023.1853.1   1.3.6.1.4.1.25623.1.1.1.1.2023.5381   1.3.6.1.4.1.25623.1.0.149062   1.3.6.1.4.1.25623.1.0.149061  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2022-45143
https://lists.apache.org/thread/yqkd183xrw3wqvnpcg3osbcryq85fkzj
https://lists.apache.org/thread/yqkd183xrw3wqvnpcg3osbcryq85fkzj
https://security.gentoo.org/glsa/202305-37
https://security.gentoo.org/glsa/202305-37




© 1998-2025 E-Soft Inc. All rights reserved.