CVE-2022-29885

Description

The documentation of Apache Tomcat 10.1.0-M1 to 10.1.0-M14, 10.0.0-M1 to 10.0.20, 9.0.13 to 9.0.62 and 8.5.38 to 8.5.78 for the EncryptInterceptor incorrectly stated it enabled Tomcat clustering to run over an untrusted network. This was not correct. While the EncryptInterceptor does provide confidentiality and integrity protection, it does not protect against all risks associated with running over any untrusted network, particularly DoS risks.

Risk Information

Base Score
7.5
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS Score
Exploitation Probability
60.112

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2022-29885 are fixed Apache Tomcat 10.0.21Windows
Vulnerabilities CVE-2022-29885 are Fixed in Apache Tomcat 10.1.0-M15Windows
Vulnerabilities CVE-2022-29885 Fixed in Apache Tomcat 9.0.63Windows
Vulnerabilities CVE-2022-29885 are Fixed in Apache Tomcat 8.5.79Windows
Vulnerabilities CVE-2022-29885 are fixed in Apache - tomcat 10.1.0Windows
Vulnerabilities CVE-2022-29885 are fixed in Apache - tomcat 10.0.21Windows
Vulnerabilities CVE-2022-29885 are fixed in Apache - tomcat 9.0.63Windows
Vulnerabilities CVE-2022-29885 are fixed in Apache - tomcat 8.5.79Windows
Vulnerabilities CVE-2022-29885 are fixed Apache Tomcat 10.0.21 (For Linux)Linux
Vulnerabilities CVE-2022-29885 are Fixed in Apache Tomcat 10.1.0-M15 (For Linux)Linux
Vulnerabilities CVE-2022-29885 Fixed in Apache Tomcat 9.0.63 (For Linux)Linux
Vulnerabilities CVE-2022-29885 are Fixed in Apache Tomcat 8.5.79 (For Linux)Linux
Servlet and JSP engine (USN-6943-1) libtomcat9-java_9.0.31-1ubuntu0.6_all.debLinux
Servlet and JSP engine (USN-6943-1) tomcat9_9.0.31-1ubuntu0.6_all.debLinux
Servlet and JSP engine (USN-6943-1) tomcat9-docs_9.0.31-1ubuntu0.6_all.debLinux
Vulnerabilities CVE-2022-29885 are fixed in Apache - tomcat for Linux 10.1.0Linux
Vulnerabilities CVE-2022-29885 are fixed in Apache - tomcat for Linux 10.0.21Linux
Vulnerabilities CVE-2022-29885 are fixed in Apache - tomcat for Linux 9.0.63Linux
Vulnerabilities CVE-2022-29885 are fixed in Apache - tomcat for Linux 8.5.79Linux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234