High severity7.5NVD Advisory· Published Jan 3, 2023· Updated Jun 17, 2026
CVE-2022-45143
CVE-2022-45143
Description
The JsonErrorReportValve in Apache Tomcat 8.5.83, 9.0.40 to 9.0.68 and 10.1.0-M1 to 10.1.1 did not escape the type, message or description values. In some circumstances these are constructed from user provided data and it was therefore possible for users to supply values that invalidated or manipulated the JSON output.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.apache.tomcat.embed:tomcat-embed-coreMaven | >= 8.5.83, < 8.5.84 | 8.5.84 |
org.apache.tomcat.embed:tomcat-embed-coreMaven | >= 9.0.40, < 9.0.69 | 9.0.69 |
org.apache.tomcat.embed:tomcat-embed-coreMaven | >= 10.1.0, < 10.1.2 | 10.1.2 |
org.apache.tomcat:tomcat-catalinaMaven | >= 10.1.0, < 10.1.2 | 10.1.2 |
org.apache.tomcat:tomcat-utilMaven | >= 8.5.83, < 8.5.84 | 8.5.84 |
org.apache.tomcat:tomcat-utilMaven | >= 9.0.40, < 9.0.69 | 9.0.69 |
Affected products
39- osv-coords18 versionspkg:rpm/opensuse/tomcat&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/tomcat10&distro=openSUSE%20Tumbleweedpkg:maven/org.apache.tomcat.embed/tomcat-embed-corepkg:maven/org.apache.tomcat/tomcat-catalinapkg:maven/org.apache.tomcat/tomcat-utilpkg:bitnami/tomcatpkg:rpm/suse/tomcat&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Web%20and%20Scripting%2015%20SP4pkg:rpm/suse/tomcat&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP3-ESPOSpkg:rpm/suse/tomcat&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP3-LTSSpkg:rpm/suse/tomcat&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP2-LTSSpkg:rpm/suse/tomcat&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP3pkg:rpm/suse/tomcat&distro=SUSE%20Manager%20Server%204.2pkg:rpm/suse/tomcat&distro=SUSE%20Enterprise%20Storage%207.1pkg:rpm/opensuse/tomcat&distro=openSUSE%20Leap%2015.4pkg:rpm/suse/tomcat&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP3-LTSSpkg:rpm/suse/tomcat&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP2pkg:rpm/suse/tomcat&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP2-LTSSpkg:rpm/suse/tomcat&distro=SUSE%20Enterprise%20Storage%207
< 9.0.43-16.1+ 17 more
- (no CPE)range: < 9.0.43-16.1
- (no CPE)range: < 10.1.14-1.1
- (no CPE)range: >= 8.5.83, < 8.5.84
- (no CPE)range: >= 10.1.0, < 10.1.2
- (no CPE)range: >= 8.5.83, < 8.5.84
- (no CPE)range: >= 9.0.40, < 9.0.69
- (no CPE)range: < 9.0.43-150200.38.1
- (no CPE)range: < 9.0.43-150200.38.1
- (no CPE)range: < 9.0.43-150200.38.1
- (no CPE)range: < 9.0.43-150200.38.1
- (no CPE)range: < 9.0.43-150200.38.1
- (no CPE)range: < 9.0.43-150200.38.1
- (no CPE)range: < 9.0.43-150200.38.1
- (no CPE)range: < 9.0.43-150200.38.1
- (no CPE)range: < 9.0.43-150200.38.1
- (no CPE)range: < 9.0.43-150200.38.1
- (no CPE)range: < 9.0.43-150200.38.1
- (no CPE)range: < 9.0.43-150200.38.1
- Apache Software Foundation/Apache Tomcatv5Range: 10.1.0-M1
cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:*+ 19 more
- cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:*range: >=9.0.40,<9.0.69
- cpe:2.3:a:apache:tomcat:8.5.83:*:*:*:*:*:*:*
- cpe:2.3:a:apache:tomcat:10.1.0:milestone1:*:*:*:*:*:*
- cpe:2.3:a:apache:tomcat:10.1.0:milestone10:*:*:*:*:*:*
- cpe:2.3:a:apache:tomcat:10.1.0:milestone11:*:*:*:*:*:*
- cpe:2.3:a:apache:tomcat:10.1.0:milestone12:*:*:*:*:*:*
- cpe:2.3:a:apache:tomcat:10.1.0:milestone13:*:*:*:*:*:*
- cpe:2.3:a:apache:tomcat:10.1.0:milestone14:*:*:*:*:*:*
- cpe:2.3:a:apache:tomcat:10.1.0:milestone15:*:*:*:*:*:*
- cpe:2.3:a:apache:tomcat:10.1.0:milestone16:*:*:*:*:*:*
- cpe:2.3:a:apache:tomcat:10.1.0:milestone17:*:*:*:*:*:*
- cpe:2.3:a:apache:tomcat:10.1.0:milestone2:*:*:*:*:*:*
- cpe:2.3:a:apache:tomcat:10.1.0:milestone3:*:*:*:*:*:*
- cpe:2.3:a:apache:tomcat:10.1.0:milestone4:*:*:*:*:*:*
- cpe:2.3:a:apache:tomcat:10.1.0:milestone5:*:*:*:*:*:*
- cpe:2.3:a:apache:tomcat:10.1.0:milestone6:*:*:*:*:*:*
- cpe:2.3:a:apache:tomcat:10.1.0:milestone7:*:*:*:*:*:*
- cpe:2.3:a:apache:tomcat:10.1.0:milestone8:*:*:*:*:*:*
- cpe:2.3:a:apache:tomcat:10.1.0:milestone9:*:*:*:*:*:*
- cpe:2.3:a:apache:tomcat:10.1.1:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
8- github.com/advisories/GHSA-rq2w-37h9-vg94ghsaADVISORY
- lists.apache.org/thread/yqkd183xrw3wqvnpcg3osbcryq85fkzjnvdMailing ListVendor AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2022-45143ghsaADVISORY
- security.gentoo.org/glsa/202305-37nvdThird Party AdvisoryWEB
- github.com/apache/tomcat/commit/0cab3a56bd89f70e7481bb0d68395dc7e130dbbfghsaWEB
- github.com/apache/tomcat/commit/6a0ac6a438cbbb66b6e9c5223842f53bf0cb50aaghsaWEB
- github.com/apache/tomcat/commit/b336f4e58893ea35114f1e4a415657f723b1298eghsaWEB
- security.netapp.com/advisory/ntap-20230216-0009/nvd
News mentions
0No linked articles in our index yet.