In Apache Tomcat 10.1.0-M1 to 10.1.0-M16, 10.0.0-M1 to 10.0.22, 9.0.30 to 9.0.64 and 8.5.50 to 8.5.81 the Form authentication example in the examples web application displayed user provided data without filtering, exposing a XSS vulnerability.
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | — | Upgrade tomcat-webappsUpgrade tomcat-admin-webappsUpgrade tomcat-jsp-2.3-apiUpgrade tomcat-javadocUpgrade tomcat-jsvcUpgrade tomcat-servlet-3.1-apiUpgrade tomcat-docs-webappUpgrade tomcat-libUpgrade tomcatUpgrade tomcat-el-3.0-api | Sep 28, 2023 | Jun 23, 2022 |
| Apache Tomcat | — | Upgrade Apache Tomcat to 9.0.65Upgrade Apache Tomcat to 10.1.0Upgrade Apache Tomcat to 8.5.82Upgrade Apache Tomcat to 10.0.23Upgrade Apache Tomcat to the latest available version | Jun 24, 2022 | Jun 23, 2022 |
| Debian | — | Upgrade tomcat9 | Jul 30, 2024 | Jun 23, 2022 |
| Freebsd | — | Upgrade tomcat-develUpgrade tomcat10Upgrade tomcat9Upgrade tomcat85Upgrade tomcat | Nov 4, 2022 | Aug 14, 2022 |
| Gentoo Linux | — | Upgrade www-servers/tomcat. | Aug 22, 2022 | Jun 23, 2022 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub