{"schema_version":"1.7.3","id":"GHSA-rq2w-37h9-vg94","published":"2023-01-03T21:30:21Z","modified":"2024-04-23T22:00:59.346897Z","aliases":["BIT-tomcat-2022-45143","CVE-2022-45143"],"summary":"Apache Tomcat improperly escapes input from JsonErrorReportValve","details":"The `JsonErrorReportValve` in Apache Tomcat 8.5.83, 9.0.40 to 9.0.68 and 10.1.0-M1 to 10.1.1 does not escape the `type`, `message` or `description` values. In some circumstances these are constructed from user provided data and it was therefore possible for users to supply values that invalidated or manipulated the JSON output.","affected":[{"package":{"name":"org.apache.tomcat.embed:tomcat-embed-core","ecosystem":"Maven","purl":"pkg:maven/org.apache.tomcat.embed/tomcat-embed-core"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"8.5.83"},{"fixed":"8.5.84"}]}],"versions":["8.5.83"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/01/GHSA-rq2w-37h9-vg94/GHSA-rq2w-37h9-vg94.json"}},{"package":{"name":"org.apache.tomcat.embed:tomcat-embed-core","ecosystem":"Maven","purl":"pkg:maven/org.apache.tomcat.embed/tomcat-embed-core"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"9.0.40"},{"fixed":"9.0.69"}]}],"versions":["9.0.40","9.0.41","9.0.43","9.0.44","9.0.45","9.0.46","9.0.48","9.0.50","9.0.52","9.0.53","9.0.54","9.0.55","9.0.56","9.0.58","9.0.59","9.0.60","9.0.62","9.0.63","9.0.64","9.0.65","9.0.67","9.0.68"],"database_specific":{"last_known_affected_version_range":"<= 9.0.68","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/01/GHSA-rq2w-37h9-vg94/GHSA-rq2w-37h9-vg94.json"}},{"package":{"name":"org.apache.tomcat.embed:tomcat-embed-core","ecosystem":"Maven","purl":"pkg:maven/org.apache.tomcat.embed/tomcat-embed-core"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"10.1.0"},{"fixed":"10.1.2"}]}],"versions":["10.1.0","10.1.1"],"database_specific":{"last_known_affected_version_range":"<= 10.1.1","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/01/GHSA-rq2w-37h9-vg94/GHSA-rq2w-37h9-vg94.json"}},{"package":{"name":"org.apache.tomcat:tomcat-catalina","ecosystem":"Maven","purl":"pkg:maven/org.apache.tomcat/tomcat-catalina"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"10.1.0"},{"fixed":"10.1.2"}]}],"versions":["10.1.0","10.1.1"],"database_specific":{"last_known_affected_version_range":"<= 10.1.1","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/01/GHSA-rq2w-37h9-vg94/GHSA-rq2w-37h9-vg94.json"}},{"package":{"name":"org.apache.tomcat:tomcat-util","ecosystem":"Maven","purl":"pkg:maven/org.apache.tomcat/tomcat-util"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"8.5.83"},{"fixed":"8.5.84"}]}],"versions":["8.5.83"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/01/GHSA-rq2w-37h9-vg94/GHSA-rq2w-37h9-vg94.json"}},{"package":{"name":"org.apache.tomcat:tomcat-util","ecosystem":"Maven","purl":"pkg:maven/org.apache.tomcat/tomcat-util"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"9.0.40"},{"fixed":"9.0.69"}]}],"versions":["9.0.40","9.0.41","9.0.43","9.0.44","9.0.45","9.0.46","9.0.48","9.0.50","9.0.52","9.0.53","9.0.54","9.0.55","9.0.56","9.0.58","9.0.59","9.0.60","9.0.62","9.0.63","9.0.64","9.0.65","9.0.67","9.0.68"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/01/GHSA-rq2w-37h9-vg94/GHSA-rq2w-37h9-vg94.json"}}],"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-45143"},{"type":"WEB","url":"https://github.com/apache/tomcat/commit/0cab3a56bd89f70e7481bb0d68395dc7e130dbbf"},{"type":"WEB","url":"https://github.com/apache/tomcat/commit/6a0ac6a438cbbb66b6e9c5223842f53bf0cb50aa"},{"type":"WEB","url":"https://github.com/apache/tomcat/commit/b336f4e58893ea35114f1e4a415657f723b1298e"},{"type":"PACKAGE","url":"https://github.com/apache/tomcat"},{"type":"WEB","url":"https://lists.apache.org/thread/yqkd183xrw3wqvnpcg3osbcryq85fkzj"},{"type":"WEB","url":"https://security.gentoo.org/glsa/202305-37"}],"database_specific":{"cwe_ids":["CWE-116","CWE-74"],"github_reviewed":true,"github_reviewed_at":"2023-01-05T12:02:50Z","nvd_published_at":"2023-01-03T19:15:00Z","severity":"HIGH"},"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"}]}