Apache Tomcat Examples XSS Vulnerability CVE-2022-34305 

Issue date: 21-09-2022
Affects versions: 15.1, 14.7, 13.4

Security Issue ID

SECURITY-350

Affected Product Version(s)

15.1.0, 14.7.8, 13.4.18, and all previous versions


Severity 

Medium


Description

CVE-2022-34305

In Apache Tomcat 10.1.0-M1 to 10.1.0-M16, 10.0.0-M1 to 10.0.22, 9.0.30 to 9.0.64 and 8.5.50 to 8.5.81 the Form authentication example in the examples web application displayed user provided data without filtering, exposing a XSS vulnerability.

Tomcat web application examples are not part of the our product deployment so the vulnerability is not applicable.

Instructions

Verify that the tomcat examples application is not included when deploying with self-hosted or private cloud infrastructure.