Medium severity6.1NVD Advisory· Published Jun 23, 2022· Updated Jun 17, 2026
CVE-2022-34305
CVE-2022-34305
Description
In Apache Tomcat 10.1.0-M1 to 10.1.0-M16, 10.0.0-M1 to 10.0.22, 9.0.30 to 9.0.64 and 8.5.50 to 8.5.81 the Form authentication example in the examples web application displayed user provided data without filtering, exposing a XSS vulnerability.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.apache.tomcat:tomcatMaven | >= 10.1.0-M1, < 10.1.0-M17 | 10.1.0-M17 |
org.apache.tomcat:tomcatMaven | >= 10.0.0-M1, < 10.0.22 | 10.0.22 |
org.apache.tomcat:tomcatMaven | >= 9.0.30, < 9.0.65 | 9.0.65 |
org.apache.tomcat:tomcatMaven | >= 8.5.50, < 8.5.82 | 8.5.82 |
Affected products
20cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:*+ 16 more
- cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:*range: >=8.5.50,<=8.5.81
- cpe:2.3:a:apache:tomcat:10.1.0:milestone1:*:*:*:*:*:*
- cpe:2.3:a:apache:tomcat:10.1.0:milestone10:*:*:*:*:*:*
- cpe:2.3:a:apache:tomcat:10.1.0:milestone11:*:*:*:*:*:*
- cpe:2.3:a:apache:tomcat:10.1.0:milestone12:*:*:*:*:*:*
- cpe:2.3:a:apache:tomcat:10.1.0:milestone13:*:*:*:*:*:*
- cpe:2.3:a:apache:tomcat:10.1.0:milestone14:*:*:*:*:*:*
- cpe:2.3:a:apache:tomcat:10.1.0:milestone15:*:*:*:*:*:*
- cpe:2.3:a:apache:tomcat:10.1.0:milestone16:*:*:*:*:*:*
- cpe:2.3:a:apache:tomcat:10.1.0:milestone2:*:*:*:*:*:*
- cpe:2.3:a:apache:tomcat:10.1.0:milestone3:*:*:*:*:*:*
- cpe:2.3:a:apache:tomcat:10.1.0:milestone4:*:*:*:*:*:*
- cpe:2.3:a:apache:tomcat:10.1.0:milestone5:*:*:*:*:*:*
- cpe:2.3:a:apache:tomcat:10.1.0:milestone6:*:*:*:*:*:*
- cpe:2.3:a:apache:tomcat:10.1.0:milestone7:*:*:*:*:*:*
- cpe:2.3:a:apache:tomcat:10.1.0:milestone8:*:*:*:*:*:*
- cpe:2.3:a:apache:tomcat:10.1.0:milestone9:*:*:*:*:*:*
- Apache Software Foundation/Apache Tomcatv5Range: Apache Tomcat 8.5 8.5.50 to 8.5.81
- ghsa-coords2 versions
>= 10.1.0-M1, < 10.1.0-M17+ 1 more
- (no CPE)range: >= 10.1.0-M1, < 10.1.0-M17
- (no CPE)range: >= 8.5.50, < 8.5.82
Patches
Vulnerability mechanics
References
7- www.openwall.com/lists/oss-security/2022/06/23/1nvdMailing ListThird Party AdvisoryWEB
- github.com/advisories/GHSA-6j88-6whg-x687ghsaADVISORY
- lists.apache.org/thread/k04zk0nq6w57m72w5gb0r6z9ryhmvr4knvdMailing ListRelease NotesThird Party AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2022-34305ghsaADVISORY
- security.gentoo.org/glsa/202208-34nvdThird Party AdvisoryWEB
- security.netapp.com/advisory/ntap-20220729-0006/nvdThird Party Advisory
- security.netapp.com/advisory/ntap-20220729-0006ghsaWEB
News mentions
0No linked articles in our index yet.