CVE-2022-45143: Apache Tomcat: JsonErrorReportValve escaping
The JsonErrorReportValve in Apache Tomcat 8.5.83, 9.0.40 to 9.0.68 and 10.1.0-M1 to 10.1.1 does not escape the type, message or description values. In some circumstances these are constructed from user provided data and it was therefore possible for users to supply values that invalidated or manipulated the JSON output.
Other sources
The JsonErrorReportValve in Apache Tomcat 8.5.83, 9.0.40 to 9.0.68 and 10.1.0-M1 to 10.1.1 did not escape the type, message or description values. In some circumstances these are constructed from user provided data and it was therefore possible for users to supply values that invalidated or manipulated the JSON output.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-45143?
CVE-2022-45143 is a vulnerability in Apache Tomcat versions 8.5.83, 9.0.40 to 9.0.68, and 10.1.0-M1 to 10.1.1 that allows users to supply values that invalidate or execute arbitrary code.
How severe is CVE-2022-45143?
CVE-2022-45143 has a severity rating of 7.5 (High).
What is the affected software by CVE-2022-45143?
The affected software by CVE-2022-45143 includes Apache Tomcat versions 8.5.83, 9.0.40 to 9.0.68, and 10.1.0-M1 to 10.1.1.
How can I fix CVE-2022-45143?
To fix CVE-2022-45143, you should upgrade to Apache Tomcat version 10.1.2, 9.0.69, or 8.5.84.
Where can I find more information about CVE-2022-45143?
You can find more information about CVE-2022-45143 on the NVD website, Apache Tomcat mailing list, and the Apache Tomcat GitHub commit.