PT-2022-3076 · Apache+4 · Apache Tomcat+4

Mark Thomas

·

Published

2022-06-23

·

Updated

2026-05-18

·

CVE-2022-34305

CVSS v2.0

6.4

Medium

VectorAV:N/AC:L/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions Apache Tomcat versions 8.5.50 through 8.5.81 Apache Tomcat versions 9.0.30 through 9.0.64 Apache Tomcat versions 10.0.0-M1 through 10.0.22 Apache Tomcat versions 10.1.0-M1 through 10.1.0-M16
Description The Form authentication example in the examples web application displayed user-provided data without filtering, exposing a cross-site scripting (XSS) issue. This could allow a remote attacker to conduct an XSS attack.
Recommendations For Apache Tomcat versions 8.5.50 through 8.5.81, update to a version that includes the fix for this issue. For Apache Tomcat versions 9.0.30 through 9.0.64, update to a version that includes the fix for this issue. For Apache Tomcat versions 10.0.0-M1 through 10.0.22, update to a version that includes the fix for this issue. For Apache Tomcat versions 10.1.0-M1 through 10.1.0-M16, update to a version that includes the fix for this issue. As a temporary workaround, consider disabling the Form authentication example in the examples web application until a patch is available.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2024_1134
ALSA-2024_1444
ALSA-2025_11333
ALSA-2025_11335
ALSA-2025_16880
ALSA-2025_3645
ALSA-2025_3683
ALT-PU-2023-8058
ALT-PU-2025-2379
ALT-PU-2025-9146
BDU:2022-03746
BIT-TOMCAT-2022-34305
CLEANSTART-2026-AJ47488
CLEANSTART-2026-AM95501
CLEANSTART-2026-CD66042
CLEANSTART-2026-GR86205
CLEANSTART-2026-KB11938
CLEANSTART-2026-MR27796
CLEANSTART-2026-RH10099
CLEANSTART-2026-RK94800
CLEANSTART-2026-SJ80413
CLEANSTART-2026-TN71701
CLEANSTART-2026-UZ56639
CLEANSTART-2026-XI02879
CLEANSTART-2026-XP03839
CLEANSTART-2026-XP58111
CVE-2022-34305
GHSA-6J88-6WHG-X687
MGASA-2023-0138
ROSA-SA-2023-2258

Affected Products

Alt Linux
Apache Tomcat
Astra Linux
Debian
Red Os