Name | CVE-2022-29885 |
Description | The documentation of Apache Tomcat 10.1.0-M1 to 10.1.0-M14, 10.0.0-M1 to 10.0.20, 9.0.13 to 9.0.62 and 8.5.38 to 8.5.78 for the EncryptInterceptor incorrectly stated it enabled Tomcat clustering to run over an untrusted network. This was not correct. While the EncryptInterceptor does provide confidentiality and integrity protection, it does not protect against all risks associated with running over any untrusted network, particularly DoS risks. |
Source | CVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more) |
References | DLA-3160-1, DSA-5265-1 |
The table below lists information on source packages.
Source Package | Release | Version | Status |
---|---|---|---|
tomcat7 (PTS) | jessie, jessie (lts) | 7.0.56-3+really7.0.109-1+deb8u6 | fixed |
stretch | 7.0.75-1 | vulnerable | |
tomcat8 (PTS) | jessie, jessie (lts) | 8.0.14-1+deb8u28 | fixed |
stretch (security) | 8.5.54-0+deb9u8 | vulnerable | |
stretch (lts), stretch | 8.5.54-0+deb9u15 | fixed | |
tomcat9 (PTS) | buster (security), buster, buster (lts) | 9.0.31-1~deb10u12 | fixed |
bullseye (security), bullseye | 9.0.43-2~deb11u10 | fixed | |
bookworm | 9.0.70-2 | fixed | |
sid, trixie | 9.0.95-1 | fixed |
The information below is based on the following data on fixed versions.
Package | Type | Release | Fixed Version | Urgency | Origin | Debian Bugs |
---|---|---|---|---|---|---|
tomcat7 | source | jessie | (not affected) | |||
tomcat7 | source | stretch | (unfixed) | end-of-life | ||
tomcat7 | source | (unstable) | (unfixed) | |||
tomcat8 | source | jessie | (not affected) | |||
tomcat8 | source | stretch | 8.5.54-0+deb9u9 | |||
tomcat8 | source | (unstable) | (unfixed) | |||
tomcat9 | source | buster | 9.0.31-1~deb10u7 | DLA-3160-1 | ||
tomcat9 | source | bullseye | 9.0.43-2~deb11u4 | DSA-5265-1 | ||
tomcat9 | source | (unstable) | 9.0.63-1 |
[stretch] - tomcat8 <postponed> (Minor issue)
https://github.com/apache/tomcat/commit/eaafd28296c54d983e28a47953c1f5cb2c334f48 (9.0.63)
https://github.com/apache/tomcat/commit/b679bc627f5a4ea6510af95adfb7476b07eba890 (8.5.79)
[jessie] - tomcat7 <not-affected> (Misleading documentation bits introduced in 2019 and not backported to 7.0.x)
[jessie] - tomcat8 <not-affected> (Misleading documentation bits introduced in 2019 and not backported to 8.0.x)