CVE-2022-29885
🟡 Monitoruj
Błędna dokumentacja w Apache Tomcat sugeruje bezpieczeństwo klastrów w niezaufanej sieci, co jest nieprawdziwe.
CVSS
7.5
EPSS
73.5%
Exploit
none
Vendor
apache
Opis źródłowy (NVD)
The documentation of Apache Tomcat 10.1.0-M1 to 10.1.0-M14, 10.0.0-M1 to 10.0.20, 9.0.13 to 9.0.62 and 8.5.38 to 8.5.78 for the EncryptInterceptor incorrectly stated it enabled Tomcat clustering to run over an untrusted network. This was not correct. While the EncryptInterceptor does provide confidentiality and integrity protection, it does not protect against all risks associated with running over any untrusted network, particularly DoS risks.
dos
Brak patcha
Źródła i daty
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 7.5 |
| CISA KEV (aktywnie wykorzystywane) | Nie |
| FIRST EPSS (prawdopodobieństwo exploita) | 73.5% |
| Opublikowano (NVD) | 2022-05-12 08:15:07 UTC |
| Ostatnia modyfikacja (NVD) | 2026-10-08 22:17:20 UTC |
Referencje
- http://packetstormsecurity.com/files/171728/Apache-Tomcat-10.1-Denial-Of-Service.html ([email protected])
- https://lists.apache.org/thread/2b4qmhbcyqvc7dyfpjyx54c03x65vhcv ([email protected]) [Mailing List, Mitigation, Vendor Advisory]
- https://lists.debian.org/debian-lts-announce/2022/10/msg00029.html ([email protected]) [Mailing List, Third Party Advisory]
- https://security.netapp.com/advisory/ntap-20220629-0002/ ([email protected]) [Third Party Advisory]
- https://www.debian.org/security/2022/dsa-5265 ([email protected]) [Third Party Advisory]
- https://www.oracle.com/security-alerts/cpujul2022.html ([email protected]) [Patch, Third Party Advisory]