Record summary

CVE-2022-34305 has a selected CVSS score of 6.1 (medium); EIP currently links 1 repository PoC and 1 Nuclei template.

Description

In Apache Tomcat 10.1.0-M1 to 10.1.0-M16, 10.0.0-M1 to 10.0.22, 9.0.30 to 9.0.64 and 8.5.50 to 8.5.81 the Form authentication example in the examples web application displayed user provided data without filtering, exposing a XSS vulnerability.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Nov 9, 2023 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Repository PoCs
1
Nuclei templates
1

Affected products and versions

3
ProductSourceVersion rangeStatus
VulnCheckVersion data not supplied
CVE ListApache Tomcat 8.5 8.5.50 to 8.5.81affected
Apache Tomcat 9 9.0.30 to 9.0.64affected
Apache Tomcat 10.0 10.0.0-M1 to 10.0.22affected
Apache Tomcat 10.1 10.1.0-M1 to 10.1.0-M16affected
GitHub Advisory10.1.0-M1 to < 10.1.0-M17 · Fixed in 10.1.0-M17affected
10.0.0-M1 to < 10.0.22 · Fixed in 10.0.22affected
9.0.30 to < 9.0.65 · Fixed in 9.0.65affected
8.5.50 to < 8.5.82 · Fixed in 8.5.82affected

Proofs of concept

1

Repository PoCs

GitHubzeroc00I/CVE-2022-34305Repository PoCby zeroc00IStars: 1Not analyzed1 file

841 B

GitHub

PoC details

Nuclei templates

1
ProjectDiscoveryMEDIUMApache Tomcat Examples Web Application - Cross-Site ScriptingCVSS 6.1

Apache Tomcat 8.5.50 to 8.5.81, 9.0.30 to 9.0.64, 10.0.0-M1 to 10.0.22, and 10.1.0-M1 to 10.1.0-M16 contain a reflected cross-site scripting caused by displaying unfiltered user data in the Form authentication example, letting attackers execute scripts in victim browsers, exploit requires attacker to craft malicious input.

Impact

Attackers can execute malicious scripts in victim browsers, leading to session hijacking, defacement, or redirection.

Remediation

Update to the latest version of Apache Tomcat where this issue is fixed.

WeaknessesCWE-79
AuthorsSourabh-Sahu
Template tagscvecve2022xssapachetomcatauthenticatedvkev
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:*
Shodan: cpe:"cpe:2.3:a:apache:tomcat"
Shodan: http.component:"apache tomcat"
FOFA: body="apache tomcat"
Google: site:*/examples/jsp/snp/snoop.jsp

Source: ProjectDiscovery

References

5