CVE-2022-45143
The JsonErrorReportValve in Apache Tomcat 8.5.83, 9.0.40 to 9.0.68 and 10.1.0-M1 to 10.1.1 did not escape the type, message or description values. In some circumstances these are constructed from user provided data and it was therefore possible for users to supply values that invalidated or manipulated the JSON output.
- Affected products
- Alt Linux, Apache Tomcat, Astra Linux, Confluence, Red Os, Suse
- Apache Tomcat
- < 9.0.69, 8.5.83, 10.1.0, 10.1.1
- Fix
- Available
- CVSS 3.1
- 7.5 HIGH
- EPSS
- 2.5% (83th percentile)
- Weakness
- CWE-116
- NVD status
- Modified
- Published
- 2023-01-03
CVE-2022-45143 at NVD
No indexed exploits for CVE-2022-45143 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2022-45143 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.