Description
The JsonErrorReportValve in Apache Tomcat 8.5.83, 9.0.40 to 9.0.68 and 10.1.0-M1 to 10.1.1 did not escape the type, message or description values. In some circumstances these are constructed from user provided data and it was therefore possible for users to supply values that invalidated or manipulated the JSON output.
Remediation
References
https://lists.apache.org/thread/yqkd183xrw3wqvnpcg3osbcryq85fkzj
https://security.gentoo.org/glsa/202305-37
https://security.netapp.com/advisory/ntap-20230216-0009/
Related Vulnerabilities
CVE-2023-46750 Vulnerability in maven package org.apache.shiro:shiro-web
CVE-2022-2932 Vulnerability in maven package org.webjars.npm:mobiledoc-kit
CVE-2022-45385 Vulnerability in maven package org.jenkins-ci.plugins:dockerhub-notification
CVE-2023-37478 Vulnerability in npm package @pnpm/exe
CVE-2017-3159 Vulnerability in maven package org.apache.camel:camel-snakeyaml