QID 150541
Date Published: 2022-07-07
QID 150541: Apache Tomcat Cross-Site Scripting(XSS) Vulnerability (CVE-2022-34305)
Apache Tomcat is an open source web server and servlet container developed by the Apache Software Foundation.
In affected versions of Apache Tomcat, the Form authentication example in the examples web application displayed user provided data without filtering, exposing a XSS vulnerability.
Affected Versions:
Apache Tomcat 10.1.0-M1 to 10.1.0-M16
Apache Tomcat 10.0.0-M1 to 10.0.22
Apache Tomcat 9.0.30 to 9.0.64
Apache Tomcat 8.5.50 to 8.5.81
QID Detection Logic (Unauthenticated):
This QID sends a HTTP GET request to a invalid URL and based on the response confirms the vulnerable instance of Apache Tomcat running on the host.
Successful exploitation could allow an attacker to execute arbitrary JavaScript code in the context of the interface or allow the attacker to access sensitive, browser-based information.
- Apache Tomcat -
lists.apache.org/thread/k04zk0nq6w57m72w5gb0r6z9ryhmvr4k
CVEs related to QID 150541
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| Apache Tomcat |
|