PT-2022-3076 · Apache+4 · Apache Tomcat+4

·

CVE-2022-34305

·

Published

2022-06-23

·

Updated

2026-07-21

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Apache Tomcat versions 8.5.50 through 8.5.81 Apache Tomcat versions 9.0.30 through 9.0.64 Apache Tomcat versions 10.0.0-M1 through 10.0.22 Apache Tomcat versions 10.1.0-M1 through 10.1.0-M16
Description The Form authentication example in the examples web application displayed user-provided data without filtering, exposing a cross-site scripting (XSS) issue. This could allow a remote attacker to conduct an XSS attack.
Recommendations For Apache Tomcat versions 8.5.50 through 8.5.81, update to a version that includes the fix for this issue. For Apache Tomcat versions 9.0.30 through 9.0.64, update to a version that includes the fix for this issue. For Apache Tomcat versions 10.0.0-M1 through 10.0.22, update to a version that includes the fix for this issue. For Apache Tomcat versions 10.1.0-M1 through 10.1.0-M16, update to a version that includes the fix for this issue. As a temporary workaround, consider disabling the Form authentication example in the examples web application until a patch is available.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2024_1134
ALSA-2024_1444
ALSA-2025_11333
ALSA-2025_11335
ALSA-2025_16880
ALSA-2025_3645
ALSA-2025_3683
ALT-PU-2023-8058
ALT-PU-2025-2379
ALT-PU-2025-9146
BDU:2022-03746
BIT-TOMCAT-2022-34305
CLEANSTART-2026-AJ47488
CLEANSTART-2026-AM95501
CLEANSTART-2026-CD66042
CLEANSTART-2026-FZ85220
CLEANSTART-2026-GR86205
CLEANSTART-2026-JJ28789
CLEANSTART-2026-KB11938
CLEANSTART-2026-MR27796
CLEANSTART-2026-RH10099
CLEANSTART-2026-RK94800
CLEANSTART-2026-SJ80413
CLEANSTART-2026-TN71701
CLEANSTART-2026-UZ56639
CLEANSTART-2026-XI02879
CLEANSTART-2026-XP03839
CLEANSTART-2026-XP58111
CLEANSTART-2026-ZZ29110
CVE-2022-34305
GHSA-6J88-6WHG-X687
MGASA-2023-0138
ROSA-SA-2023-2258

Affected Products

Alt Linux
Apache Tomcat
Astra Linux
Debian
Red Os