CVE-2022-45143

HIGH

Apache Tomcat <10.1.1 - Info Disclosure

Title source: llm
STIX 2.1

Description

The JsonErrorReportValve in Apache Tomcat 8.5.83, 9.0.40 to 9.0.68 and 10.1.0-M1 to 10.1.1 did not escape the type, message or description values. In some circumstances these are constructed from user provided data and it was therefore possible for users to supply values that invalidated or manipulated the JSON output.

References (3)

Core 3

Scores

CVSS v3 7.5
EPSS 0.0250
EPSS Percentile 82.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-116
Status published
Products (7)
apache/tomcat 8.5.83
apache/tomcat 10.1.0 milestone1 (17 CPE variants)
apache/tomcat 10.1.1
apache/tomcat 9.0.40 - 9.0.69
org.apache.tomcat/tomcat-catalina 10.1.0 - 10.1.2Maven
org.apache.tomcat/tomcat-util 8.5.83 - 8.5.84Maven
org.apache.tomcat.embed/tomcat-embed-core 8.5.83 - 8.5.84Maven
Published Jan 03, 2023
Tracked Since Feb 18, 2026