VYPR
Medium severity6.1NVD Advisory· Published Jun 23, 2022· Updated Jun 17, 2026

CVE-2022-34305

CVE-2022-34305

Description

In Apache Tomcat 10.1.0-M1 to 10.1.0-M16, 10.0.0-M1 to 10.0.22, 9.0.30 to 9.0.64 and 8.5.50 to 8.5.81 the Form authentication example in the examples web application displayed user provided data without filtering, exposing a XSS vulnerability.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
org.apache.tomcat:tomcatMaven
>= 10.1.0-M1, < 10.1.0-M1710.1.0-M17
org.apache.tomcat:tomcatMaven
>= 10.0.0-M1, < 10.0.2210.0.22
org.apache.tomcat:tomcatMaven
>= 9.0.30, < 9.0.659.0.65
org.apache.tomcat:tomcatMaven
>= 8.5.50, < 8.5.828.5.82

Affected products

20
  • Apache/Tomcat17 versions
    cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:*+ 16 more
    • cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:*range: >=8.5.50,<=8.5.81
    • cpe:2.3:a:apache:tomcat:10.1.0:milestone1:*:*:*:*:*:*
    • cpe:2.3:a:apache:tomcat:10.1.0:milestone10:*:*:*:*:*:*
    • cpe:2.3:a:apache:tomcat:10.1.0:milestone11:*:*:*:*:*:*
    • cpe:2.3:a:apache:tomcat:10.1.0:milestone12:*:*:*:*:*:*
    • cpe:2.3:a:apache:tomcat:10.1.0:milestone13:*:*:*:*:*:*
    • cpe:2.3:a:apache:tomcat:10.1.0:milestone14:*:*:*:*:*:*
    • cpe:2.3:a:apache:tomcat:10.1.0:milestone15:*:*:*:*:*:*
    • cpe:2.3:a:apache:tomcat:10.1.0:milestone16:*:*:*:*:*:*
    • cpe:2.3:a:apache:tomcat:10.1.0:milestone2:*:*:*:*:*:*
    • cpe:2.3:a:apache:tomcat:10.1.0:milestone3:*:*:*:*:*:*
    • cpe:2.3:a:apache:tomcat:10.1.0:milestone4:*:*:*:*:*:*
    • cpe:2.3:a:apache:tomcat:10.1.0:milestone5:*:*:*:*:*:*
    • cpe:2.3:a:apache:tomcat:10.1.0:milestone6:*:*:*:*:*:*
    • cpe:2.3:a:apache:tomcat:10.1.0:milestone7:*:*:*:*:*:*
    • cpe:2.3:a:apache:tomcat:10.1.0:milestone8:*:*:*:*:*:*
    • cpe:2.3:a:apache:tomcat:10.1.0:milestone9:*:*:*:*:*:*
  • Apache Software Foundation/Apache Tomcatv5
    Range: Apache Tomcat 8.5 8.5.50 to 8.5.81
  • ghsa-coords2 versions
    >= 10.1.0-M1, < 10.1.0-M17+ 1 more
    • (no CPE)range: >= 10.1.0-M1, < 10.1.0-M17
    • (no CPE)range: >= 8.5.50, < 8.5.82

Patches

Vulnerability mechanics

References

7

News mentions

0

No linked articles in our index yet.