Apache Tomcat improperly escapes input from JsonErrorReportValve
High severity
GitHub Reviewed
Published
Jan 3, 2023
to the GitHub Advisory Database
•
Updated Apr 23, 2024
Package
Affected versions
= 8.5.83
>= 9.0.40, <= 9.0.68
>= 10.1.0, <= 10.1.1
Patched versions
8.5.84
9.0.69
10.1.2
Description
Published by the National Vulnerability Database
Jan 3, 2023
Published to the GitHub Advisory Database
Jan 3, 2023
Reviewed
Jan 5, 2023
Last updated
Apr 23, 2024
The
JsonErrorReportValve
in Apache Tomcat 8.5.83, 9.0.40 to 9.0.68 and 10.1.0-M1 to 10.1.1 does not escape thetype
,message
ordescription
values. In some circumstances these are constructed from user provided data and it was therefore possible for users to supply values that invalidated or manipulated the JSON output.References