UBUNTU-CVE-2022-34305
Dashboard / Vulnerabilities / UBUNTU-CVE-2022-34305
Summary:
Details: In Apache Tomcat 10.1.0-M1 to 10.1.0-M16, 10.0.0-M1 to 10.0.22, 9.0.30 to 9.0.64 and 8.5.50 to 8.5.81 the Form authentication example in the examples web application displayed user provided data without filtering, exposing a XSS vulnerability.
References: https://ubuntu.com/security/CVE-2022-34305, https://lists.apache.org/thread/k04zk0nq6w57m72w5gb0r6z9ryhmvr4k, https://github.com/apache/tomcat/commit/8b60af90b99945379c2d1003277e0cabc6776bac, https://github.com/apache/tomcat/commit/5f6c88b054b0e4fbccff8b7f15974ed55d59a9f7, http://www.openwall.com/lists/oss-security/2022/06/23/1, https://www.cve.org/CVERecord?id=CVE-2022-34305
Affected packages
Package
Name: tomcat9
Purl: pkg:deb/ubuntu/tomcat9?arch=source&distro=esm-apps%2Ffocal
Affected ranges
Type: ECOSYSTEM
Events:
