BIT-tomcat-2022-29885

See a problem?
Import Source
https://github.com/bitnami/vulndb/tree/main/data/tomcat/BIT-tomcat-2022-29885.json
JSON Data
https://api.osv.dev/v1/vulns/BIT-tomcat-2022-29885
Aliases
Published
2024-03-06T11:09:24.492Z
Modified
2025-04-03T14:40:37.652Z
Summary
[none]
Details

The documentation of Apache Tomcat 10.1.0-M1 to 10.1.0-M14, 10.0.0-M1 to 10.0.20, 9.0.13 to 9.0.62 and 8.5.38 to 8.5.78 for the EncryptInterceptor incorrectly stated it enabled Tomcat clustering to run over an untrusted network. This was not correct. While the EncryptInterceptor does provide confidentiality and integrity protection, it does not protect against all risks associated with running over any untrusted network, particularly DoS risks.

Database specific
{
    "cpes": [
        "cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:*",
        "cpe:2.3:a:apache:tomcat:10.1.0:milestone10:*:*:*:*:*:*",
        "cpe:2.3:a:apache:tomcat:10.1.0:milestone11:*:*:*:*:*:*",
        "cpe:2.3:a:apache:tomcat:10.1.0:milestone12:*:*:*:*:*:*",
        "cpe:2.3:a:apache:tomcat:10.1.0:milestone13:*:*:*:*:*:*",
        "cpe:2.3:a:apache:tomcat:10.1.0:milestone14:*:*:*:*:*:*",
        "cpe:2.3:a:apache:tomcat:10.1.0:milestone1:*:*:*:*:*:*",
        "cpe:2.3:a:apache:tomcat:10.1.0:milestone2:*:*:*:*:*:*",
        "cpe:2.3:a:apache:tomcat:10.1.0:milestone3:*:*:*:*:*:*",
        "cpe:2.3:a:apache:tomcat:10.1.0:milestone4:*:*:*:*:*:*",
        "cpe:2.3:a:apache:tomcat:10.1.0:milestone5:*:*:*:*:*:*",
        "cpe:2.3:a:apache:tomcat:10.1.0:milestone6:*:*:*:*:*:*",
        "cpe:2.3:a:apache:tomcat:10.1.0:milestone7:*:*:*:*:*:*",
        "cpe:2.3:a:apache:tomcat:10.1.0:milestone8:*:*:*:*:*:*",
        "cpe:2.3:a:apache:tomcat:10.1.0:milestone9:*:*:*:*:*:*"
    ],
    "severity": "High"
}
References

Affected packages

Bitnami / tomcat

Package

Name
tomcat
Purl
pkg:bitnami/tomcat

Severity

  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator

Affected ranges

Type
SEMVER
Events
Introduced
8.5.38
Fixed
8.5.79
Introduced
9.0.13
Fixed
9.0.63
Introduced
10.0.0
Fixed
10.0.21
Introduced
10.1.0-milestone1
Fixed
10.1.0
Introduced
10.1.0-milestone10
Fixed
10.1.0
Introduced
10.1.0-milestone11
Fixed
10.1.0
Introduced
10.1.0-milestone12
Fixed
10.1.0
Introduced
10.1.0-milestone13
Fixed
10.1.0
Introduced
10.1.0-milestone14
Fixed
10.1.0
Introduced
10.1.0-milestone2
Fixed
10.1.0
Introduced
10.1.0-milestone3
Fixed
10.1.0
Introduced
10.1.0-milestone4
Fixed
10.1.0
Introduced
10.1.0-milestone5
Fixed
10.1.0
Introduced
10.1.0-milestone6
Fixed
10.1.0
Introduced
10.1.0-milestone7
Fixed
10.1.0
Introduced
10.1.0-milestone8
Fixed
10.1.0
Introduced
10.1.0-milestone9
Fixed
10.1.0