Description
The JsonErrorReportValve in Apache Tomcat 8.5.83, 9.0.40 to 9.0.68 and 10.1.0-M1 to 10.1.1 did not escape the type, message or description values. In some circumstances these are constructed from user provided data and it was therefore possible for users to supply values that invalidated or manipulated the JSON output.
Remediation
References
https://lists.apache.org/thread/yqkd183xrw3wqvnpcg3osbcryq85fkzj
https://security.gentoo.org/glsa/202305-37
https://security.netapp.com/advisory/ntap-20230216-0009/
Related Vulnerabilities
CVE-2009-2625 Vulnerability in maven package xerces:xercesimpl
CVE-2021-39167 Vulnerability in npm package @openzeppelin/contracts
CVE-2022-39239 Vulnerability in npm package @netlify/ipx
CVE-2019-1003087 Vulnerability in maven package org.jenkins-ci.plugins:labmanager
CVE-2022-45207 Vulnerability in maven package org.jeecgframework.boot:jeecg-module-system