You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Path to dependency file: /dd-java-agent/instrumentation/classloading/tomcat-testing/tomcat-testing.gradle
Path to vulnerable library: /caches/modules-2/files-2.1/org.apache.tomcat/tomcat-catalina/10.0.12/1e8bf6ba47132e9076286a79cf6ef9bd4b8a2737/tomcat-catalina-10.0.12.jar
The JsonErrorReportValve in Apache Tomcat 8.5.83, 9.0.40 to 9.0.68 and 10.1.0-M1 to 10.1.1 did not escape the type, message or description values. In some circumstances these are constructed from user provided data and it was therefore possible for users to supply values that invalidated or manipulated the JSON output.
mend-for-jackfan.us.kgbot
changed the title
CVE-2022-45143 (Medium) detected in tomcat-catalina-10.0.12.jar
CVE-2022-45143 (Medium) detected in tomcat-catalina-10.0.12.jar - autoclosed
Jan 4, 2023
mend-for-jackfan.us.kgbot
changed the title
CVE-2022-45143 (Medium) detected in tomcat-catalina-10.0.12.jar
CVE-2022-45143 (Medium) detected in tomcat-catalina-10.0.12.jar - autoclosed
Jan 4, 2023
CVE-2022-45143 - Medium Severity Vulnerability
Tomcat Servlet Engine Core Classes and Standard implementations
Library home page: https://tomcat.apache.org/
Path to dependency file: /dd-java-agent/instrumentation/classloading/tomcat-testing/tomcat-testing.gradle
Path to vulnerable library: /caches/modules-2/files-2.1/org.apache.tomcat/tomcat-catalina/10.0.12/1e8bf6ba47132e9076286a79cf6ef9bd4b8a2737/tomcat-catalina-10.0.12.jar
Dependency Hierarchy:
Found in HEAD commit: 2819174635979a19573ec0ce8e3e2b63a3848079
Found in base branch: master
The JsonErrorReportValve in Apache Tomcat 8.5.83, 9.0.40 to 9.0.68 and 10.1.0-M1 to 10.1.1 did not escape the type, message or description values. In some circumstances these are constructed from user provided data and it was therefore possible for users to supply values that invalidated or manipulated the JSON output.
Publish Date: 2023-01-03
URL: CVE-2022-45143
Base Score Metrics:
Type: Upgrade version
Origin: https://lists.apache.org/thread/yqkd183xrw3wqvnpcg3osbcryq85fkzj
Release Date: 2023-01-03
Fix Resolution: 10.1.2
⛑️ Automatic Remediation is available for this issue
The text was updated successfully, but these errors were encountered: