In Apache Tomcat 10.1.0-M1 to 10.1.0-M16, 10.0.0-M1 to 10.0.22, 9.0.30 to 9.0.64 and 8.5.50 to 8.5.81 the Form authentication example in the examples web application displayed user provided data without filtering, exposing a XSS vulnerability.
CVSS Details
- CVSS 3.1 Base Score: 6.1
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | — | Upgrade tomcat-el-3.0-apiUpgrade tomcat-libUpgrade tomcat-docs-webappUpgrade tomcatUpgrade tomcat-servlet-3.1-apiUpgrade tomcat-jsvcUpgrade tomcat-jsp-2.3-apiUpgrade tomcat-javadocUpgrade tomcat-webappsUpgrade tomcat-admin-webapps | Sep 28, 2023 | Jun 23, 2022 |
| Apache Tomcat | — | Upgrade Apache Tomcat to the latest available versionUpgrade Apache Tomcat to 10.0.23Upgrade Apache Tomcat to 10.1.0Upgrade Apache Tomcat to 8.5.82Upgrade Apache Tomcat to 9.0.65 | Jun 24, 2022 | Jun 23, 2022 |
| Debian | — | Upgrade tomcat9 | Jul 30, 2024 | Jun 23, 2022 |
| Freebsd | — | Upgrade tomcat10Upgrade tomcat-develUpgrade tomcat9Upgrade tomcat85Upgrade tomcat | Nov 4, 2022 | Aug 14, 2022 |
| Gentoo Linux | — | Upgrade www-servers/tomcat. | Aug 22, 2022 | Jun 23, 2022 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub