CVE-2022-29885: EncryptInterceptor does not provide complete protection on insecure networks
Apache Tomcat is vulnerable to a denial of service, caused by an use-after-free flaw in theEncryptInterceptor in an untrusted network. By sending a specially-crafted request, a remote attacker could exploit this vulnerability to cause a denial of service condition.
Other sources
The documentation of Apache Tomcat 10.1.0-M1 to 10.1.0-M14, 10.0.0-M1 to 10.0.20, 9.0.13 to 9.0.62 and 8.5.38 to 8.5.78 for the EncryptInterceptor incorrectly stated it enabled Tomcat clustering to run over an untrusted network. This was not correct. While the EncryptInterceptor does provide confidentiality and integrity protection, it does not protect against all risks associated with running over any untrusted network, particularly DoS risks.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2022-29885?
CVE-2022-29885 is a vulnerability in Apache Tomcat that incorrectly stated it enabled Tomcat clustering to run over an untrusted network.
Which versions of Apache Tomcat are affected by CVE-2022-29885?
CVE-2022-29885 affects Apache Tomcat versions 10.1.0-M1 to 10.1.0-M14, 10.0.0-M1 to 10.0.20, 9.0.13 to 9.0.62, and 8.5.38 to 8.5.78.
What is the severity of CVE-2022-29885?
CVE-2022-29885 has a severity rating of 7.5 (high).
How can I fix CVE-2022-29885?
To fix CVE-2022-29885, you should update Apache Tomcat to version 9.0.31-1~deb10u10, 9.0.43-2~deb11u6, 9.0.43-2~deb11u9, or 9.0.70-2.
Where can I find more information about CVE-2022-29885?
You can find more information about CVE-2022-29885 on the following references: [1](http://packetstormsecurity.com/files/171728/Apache-Tomcat-10.1-Denial-Of-Service.html), [2](https://lists.apache.org/thread/2b4qmhbcyqvc7dyfpjyx54c03x65vhcv), [3](https://lists.debian.org/debian-lts-announce/2022/10/msg00029.html).