CVE-2022-23181
Publication date 27 January 2022
Last updated 5 August 2024
Ubuntu priority
Cvss 3 Severity Score
The fix for bug CVE-2020-9484 introduced a time of check, time of use vulnerability into Apache Tomcat 10.1.0-M1 to 10.1.0-M8, 10.0.0-M5 to 10.0.14, 9.0.35 to 9.0.56 and 8.5.55 to 8.5.73 that allowed a local attacker to perform actions with the privileges of the user that the Tomcat process is using. This issue is only exploitable when Tomcat is configured to persist sessions using the FileStore.
Status
Package | Ubuntu Release | Status |
---|---|---|
tomcat8 | 18.04 LTS bionic |
Fixed 8.5.39-1ubuntu1~18.04.3+esm2
|
16.04 LTS xenial |
Fixed 8.0.32-1ubuntu1.13+esm1
|
|
14.04 LTS trusty | Ignored end of standard support | |
tomcat9 | 24.04 LTS noble |
Not affected
|
22.04 LTS jammy |
Not affected
|
|
20.04 LTS focal |
Fixed 9.0.31-1ubuntu0.6
|
|
18.04 LTS bionic |
Fixed 9.0.16-3ubuntu0.18.04.2+esm2
|
|
16.04 LTS xenial | Ignored end of standard support | |
14.04 LTS trusty | Ignored end of standard support |
Get expanded security coverage with Ubuntu Pro
Reduce your average CVE exposure time from 98 days to 1 day with expanded CVE patching, ten-years security maintenance and optional support for the full stack of open-source applications. Free for personal use.
Get Ubuntu ProSeverity score breakdown
Parameter | Value |
---|---|
Base score | 7.0 · High |
Attack vector | Local |
Attack complexity | High |
Privileges required | Low |
User interaction | None |
Scope | Unchanged |
Confidentiality | High |
Integrity impact | High |
Availability impact | High |
Vector | CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H |
References
Related Ubuntu Security Notices (USN)
- USN-6943-1
- Tomcat vulnerabilities
- 1 August 2024