Bugzilla – Bug 1206840
VUL-0: CVE-2022-45143: tomcat6,tomcat: JsonErrorReportValve injection
Last modified: 2024-01-17 09:50:39 UTC
CVE-2022-45143 The JsonErrorReportValve in Apache Tomcat 8.5.83, 9.0.40 to 9.0.68 and 10.1.0-M1 to 10.1.1 did not escape the type, message or description values. In some circumstances these are constructed from user provided data and it was therefore possible for users to supply values that invalidated or manipulated the JSON output. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2022-45143 https://seclists.org/oss-sec/2023/q1/2 https://www.cve.org/CVERecord?id=CVE-2022-45143 https://lists.apache.org/thread/yqkd183xrw3wqvnpcg3osbcryq85fkzj
only affects: openSUSE:Factory/tomcat
I think now also: - SUSE:SLE-12-SP4:Update/tomcat - SUSE:SLE-15-SP1:Update/tomcat - SUSE:SLE-15-SP2:Update/tomcat are affected
GH issue https://github.com/SUSE/spacewalk/issues/20905
- openSUSE:Factory/tomcat: https://build.opensuse.org/request/show/1077842 - SUSE:SLE-15-SP2:Update: https://build.suse.de/request/show/294016 instead: - SUSE:SLE-12-SP4:Update/tomcat - SUSE:SLE-15-SP1:Update/tomcat are not affected (tomcat version: 9.0.36)
SUSE-SU-2023:1853-1: An update that solves one vulnerability can now be installed. Category: security (important) Bug References: 1206840 CVE References: CVE-2022-45143 Sources used: openSUSE Leap 15.4 (src): tomcat-9.0.43-150200.38.1 Web and Scripting Module 15-SP4 (src): tomcat-9.0.43-150200.38.1 SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS 15-SP2 (src): tomcat-9.0.43-150200.38.1 SUSE Linux Enterprise High Performance Computing ESPOS 15 SP3 (src): tomcat-9.0.43-150200.38.1 SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 (src): tomcat-9.0.43-150200.38.1 SUSE Linux Enterprise Server 15 SP2 LTSS 15-SP2 (src): tomcat-9.0.43-150200.38.1 SUSE Linux Enterprise Server 15 SP3 LTSS 15-SP3 (src): tomcat-9.0.43-150200.38.1 SUSE Linux Enterprise Server for SAP Applications 15 SP2 (src): tomcat-9.0.43-150200.38.1 SUSE Linux Enterprise Server for SAP Applications 15 SP3 (src): tomcat-9.0.43-150200.38.1 SUSE Manager Server 4.2 (src): tomcat-9.0.43-150200.38.1 SUSE Enterprise Storage 7.1 (src): tomcat-9.0.43-150200.38.1 SUSE Enterprise Storage 7 (src): tomcat-9.0.43-150200.38.1 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.