Apache Tomcat Examples XSS Vulnerability CVE-2022-34305
Issue date: 21-09-2022Affects versions: 15.1, 14.7, 13.4
Security Issue ID
SECURITY-350
Affected Product Version(s)
15.1.0, 14.7.8, 13.4.18, and all previous versions
Severity
Medium
Description
In Apache Tomcat 10.1.0-M1 to 10.1.0-M16, 10.0.0-M1 to 10.0.22, 9.0.30 to 9.0.64 and 8.5.50 to 8.5.81 the Form authentication example in the examples web application displayed user provided data without filtering, exposing a XSS vulnerability.
Tomcat web application examples are not part of the our product deployment so the vulnerability is not applicable.
Instructions
Verify that the tomcat examples application is not included when deploying with self-hosted or private cloud infrastructure.