CVE-2022-45143
published 2023-01-03CVE-2022-45143: The JsonErrorReportValve in Apache Tomcat 8.5.83, 9.0.40 to 9.0.68 and 10.1.0-M1 to 10.1.1 did not escape the type, message or description values. In some…
PriorityP342high7.5CVSS 3.1
AVNACLPRNUINSUCNIHAN
EPSS
2.50%
83.0th percentile
The JsonErrorReportValve in Apache Tomcat 8.5.83, 9.0.40 to 9.0.68 and 10.1.0-M1 to 10.1.1 did not escape the type, message or description values. In some circumstances these are constructed from user provided data and it was therefore possible for users to supply values that invalidated or manipulated the JSON output.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | >= 9.0.40 < 9.0.69 | 9.0.69 |
| apache_software_foundation | apache_tomcat | — | — |
| apache_software_foundation | apache_tomcat | 10.1.0-M1 – 10.1.1 | — |
| apache_software_foundation | apache_tomcat | 9.0.40 – 9.0.68 | — |
| atlassian | confluence_data_center | — | — |
| debian | tomcat9 | < tomcat9 9.0.70-1 (bookworm) | tomcat9 9.0.70-1 (bookworm) |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
osv7.5HIGH
vendor_apache7.5HIGH
vendor_debian7.5HIGH
vendor_oracle7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Atlassian
CVE-2022-45143: org.apache.tomcat:tomcat-catalina Vulnerability in Confluence Data Center and Server
vendor_atlassian·2023-11-21·CVSS 7.5
CVE-2022-45143 [HIGH] CVE-2022-45143: org.apache.tomcat:tomcat-catalina Vulnerability in Confluence Data Center and Server
CVE-2022-45143: org.apache.tomcat:tomcat-catalina Vulnerability in Confluence Data Center and Server
org.apache.tomcat:tomcat-catalina Vulnerability in Confluence Data Center and Server
CVE: CVE-2022-45143
Severity: HIGH
Affected products: Confluence Data Center
Oracle
Oracle Oracle Commerce Risk Matrix: Endeca Application Controller (Apache Tomcat) — CVE-2022-45143
vendor_oracle·2023-07-15·CVSS 7.5
CVE-2022-45143 [HIGH] Oracle Oracle Commerce Risk Matrix: Endeca Application Controller (Apache Tomcat) — CVE-2022-45143
Oracle Oracle Commerce Risk Matrix: Endeca Application Controller (Apache Tomcat) vulnerability
CVE: CVE-2022-45143
CVSS: 7.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujul2023 (JUL 2023)
Oracle
Oracle Oracle Commerce Risk Matrix: Content Acquisition System, Workbench (Apache Tomcat) — CVE-2022-45143
vendor_oracle·2023-04-15·CVSS 7.5
CVE-2022-45143 [HIGH] Oracle Oracle Commerce Risk Matrix: Content Acquisition System, Workbench (Apache Tomcat) — CVE-2022-45143
Oracle Oracle Commerce Risk Matrix: Content Acquisition System, Workbench (Apache Tomcat) vulnerability
CVE: CVE-2022-45143
CVSS: 7.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuapr2023 (APR 2023)
Red Hat
tomcat: JsonErrorReportValve injection
vendor_redhat·2023-01-03·CVSS 7.5
CVE-2022-45143 [HIGH] CWE-74 tomcat: JsonErrorReportValve injection
tomcat: JsonErrorReportValve injection
The JsonErrorReportValve in Apache Tomcat 8.5.83, 9.0.40 to 9.0.68 and 10.1.0-M1 to 10.1.1 did not escape the type, message or description values. In some circumstances these are constructed from user provided data and it was therefore possible for users to supply values that invalidated or manipulated the JSON output.
A flaw was found in the Tomcat package. This flaw allowed users to input an invalid JSON structure, causing unwanted behavior as it did not escape the type, message, or description values.
Statement: Although it may be rated as CVSS 7.5, it's still considered a low impact flaw as according to the advisory report from Apache, user controlled data may occur in specific cases only and may alter some specific fields only.
Red Hat Satelli
Debian
CVE-2022-45143: tomcat9 - The JsonErrorReportValve in Apache Tomcat 8.5.83, 9.0.40 to 9.0.68 and 10.1.0-M1...
vendor_debian·2022·CVSS 7.5
CVE-2022-45143 [HIGH] CVE-2022-45143: tomcat9 - The JsonErrorReportValve in Apache Tomcat 8.5.83, 9.0.40 to 9.0.68 and 10.1.0-M1...
The JsonErrorReportValve in Apache Tomcat 8.5.83, 9.0.40 to 9.0.68 and 10.1.0-M1 to 10.1.1 did not escape the type, message or description values. In some circumstances these are constructed from user provided data and it was therefore possible for users to supply values that invalidated or manipulated the JSON output.
Scope: local
bookworm: resolved (fixed in 9.0.70-1)
bullseye: resolved (fixed in 9.0.43-2~deb11u6)
forky: resolved (fixed in 9.0.70-1)
sid: resolved (fixed in 9.0.70-1)
trixie: resolved (fixed in 9.0.70-1)
Apache
Apache tomcat: CVE-2022-45143
vendor_apache·CVSS 7.5
CVE-2022-45143 [HIGH] Apache tomcat: CVE-2022-45143
Apache tomcat: CVE-2022-45143
The JsonErrorReportValve did not escape the type , message or description values. In some circumstances these are constructed from user provided data and it was therefore possible for users to supply values that invalidated or manipulated the JSON output. This was fixed with commit 0cab3a56 . This issue was identified by the Apache Tomcat Security team on 2 September 2022. The issue was made public on 3 January 2023. Affects: 8.5.83 2022-10-11 Fixed in Apache Tomcat 8.5.83 Low: Apache Tomcat request smuggling
OSV
Apache Tomcat improperly escapes input from JsonErrorReportValve
osv·2023-01-03
CVE-2022-45143 [HIGH] Apache Tomcat improperly escapes input from JsonErrorReportValve
Apache Tomcat improperly escapes input from JsonErrorReportValve
The `JsonErrorReportValve` in Apache Tomcat 8.5.83, 9.0.40 to 9.0.68 and 10.1.0-M1 to 10.1.1 does not escape the `type`, `message` or `description` values. In some circumstances these are constructed from user provided data and it was therefore possible for users to supply values that invalidated or manipulated the JSON output.
GHSA
Apache Tomcat improperly escapes input from JsonErrorReportValve
ghsa·2023-01-03
CVE-2022-45143 [HIGH] CWE-116 Apache Tomcat improperly escapes input from JsonErrorReportValve
Apache Tomcat improperly escapes input from JsonErrorReportValve
The `JsonErrorReportValve` in Apache Tomcat 8.5.83, 9.0.40 to 9.0.68 and 10.1.0-M1 to 10.1.1 does not escape the `type`, `message` or `description` values. In some circumstances these are constructed from user provided data and it was therefore possible for users to supply values that invalidated or manipulated the JSON output.
OSV
CVE-2022-45143: The JsonErrorReportValve in Apache Tomcat 8
osv·2023-01-03·CVSS 7.5
CVE-2022-45143 [HIGH] CVE-2022-45143: The JsonErrorReportValve in Apache Tomcat 8
The JsonErrorReportValve in Apache Tomcat 8.5.83, 9.0.40 to 9.0.68 and 10.1.0-M1 to 10.1.1 did not escape the type, message or description values. In some circumstances these are constructed from user provided data and it was therefore possible for users to supply values that invalidated or manipulated the JSON output.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2023-01-03
Published