
=====================================================================

                              CERT-Renater

                  Note d'Information No. 2022/VULN212

_____________________________________________________________________

DATE                : 23/06/2022

HARDWARE PLATFORM(S): /

OPERATING SYSTEM(S): Systems running Apache Tomcat versions prior to
                     10.1.0-M17, 10.0.23, 9.0.65, 8.5.82.

=====================================================================
https://lists.apache.org/thread/8zxxkn43blxrrt3krko6vmjvb8ybmz9p
_____________________________________________________________________

SECURITY] CVE-2022-34305 Apache Tomcat - XSS in examples web application
CVE-2022-34305 Apache Tomcat - XSS in examples web application

Severity: Low

Vendor: The Apache Software Foundation

Versions Affected:
Apache Tomcat 10.1.0-M1 to 10.1.0-M16
Apache Tomcat 10.0.0-M1 to 10.0.22
Apache Tomcat 9.0.30 to 9.0.64
Apache Tomcat 8.5.50 to 8.5.81

Description:
The Form authentication example in the examples web application 
displayed user provided data without filtering, exposing a XSS 
vulnerability.

Mitigation:
Users of the affected versions should apply one of the following
mitigations:
- Remove the examples web application as documented in the Tomcat
    security guide
- Upgrade to Apache Tomcat 10.1.0-M17 or later once released
- Upgrade to Apache Tomcat 10.0.23 or later once released
- Upgrade to Apache Tomcat 9.0.65 or later once released
- Upgrade to Apache Tomcat 8.5.82 or later once released

History:
2022-06-23 Original advisory

References:
[1] https://tomcat.apache.org/security-10.html
[2] https://tomcat.apache.org/security-9.html
[3] https://tomcat.apache.org/security-8.html

=========================================================
+ CERT-RENATER        |    tel : 01-53-94-20-44         +
+ 23/25 Rue Daviel    |    fax : 01-53-94-20-41         +
+ 75013 Paris         |   email:cert@support.renater.fr +
=========================================================



