摘要:
In Apache Tomcat 10.1.0-M1 to 10.1.0-M16, 10.0.0-M1 to 10.0.22, 9.0.30 to 9.0.64 and 8.5.50 to 8.5.81 the Form authentication example in the examples web application displayed user provided data without filtering, exposing a XSS vulnerability.
安全等级: Low
公告ID: KylinSec-SA-2022-2533
发布日期: 2022年10月24日
关联CVE: CVE-2022-34305
In Apache Tomcat 10.1.0-M1 to 10.1.0-M16, 10.0.0-M1 to 10.0.22, 9.0.30 to 9.0.64 and 8.5.50 to 8.5.81 the Form authentication example in the examples web application displayed user provided data without filtering, exposing a XSS vulnerability.
cve名称 | 产品 | 组件 | 是否受影响 |
---|---|---|---|
CVE-2022-34305 | KY3.4-4A | tomcat | Unaffected |
CVE-2022-34305 | KY3.4-5 | tomcat | Unaffected |
CVE-2022-34305 | KY3.5.1 | tomcat | Unaffected |