CVE-2022-34305: XSS in examples web application
In Apache Tomcat 10.1.0-M1 to 10.1.0-M16, 10.0.0-M1 to 10.0.22, 9.0.30 to 9.0.64 and 8.5.50 to 8.5.81 the Form authentication example in the examples web application displayed user provided data without filtering, exposing a XSS vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2022-34305.
What is the severity of CVE-2022-34305?
CVE-2022-34305 has a severity level of 6.1 (Medium).
Which software versions are affected by CVE-2022-34305?
CVE-2022-34305 affects Apache Tomcat versions 8.5.50 to 8.5.81, 9.0.30 to 9.0.64, and 10.0.0-M1 to 10.0.22.
What is the vulnerability in Apache Tomcat?
The vulnerability in Apache Tomcat is a Cross-Site Scripting (XSS) vulnerability caused by user-provided data not being properly filtered in the Form authentication example in the examples web application.
Are there any references for CVE-2022-34305?
Yes, you can find references for CVE-2022-34305 at the following links: [Reference 1](http://www.openwall.com/lists/oss-security/2022/06/23/1), [Reference 2](https://lists.apache.org/thread/k04zk0nq6w57m72w5gb0r6z9ryhmvr4k), [Reference 3](https://security.gentoo.org/glsa/202208-34)