In Apache Tomcat 10.1.0-M1 to 10.1.0-M16, 10.0.0-M1 to 10.0.22, 9.0.30 to 9.0.64 and 8.5.50 to 8.5.81 the Form authentication example in the examples web application displayed user provided data without filtering, exposing a XSS vulnerability.
{
"versions": [
{
"introduced": "8.5.50"
},
{
"last_affected": "8.5.81"
},
{
"introduced": "9.0.30"
},
{
"last_affected": "9.0.64"
},
{
"introduced": "10.0.0"
},
{
"last_affected": "10.0.22"
},
{
"introduced": "0"
},
{
"last_affected": "10.1.0-milestone1"
},
{
"introduced": "0"
},
{
"last_affected": "10.1.0-milestone10"
},
{
"introduced": "0"
},
{
"last_affected": "10.1.0-milestone11"
},
{
"introduced": "0"
},
{
"last_affected": "10.1.0-milestone12"
},
{
"introduced": "0"
},
{
"last_affected": "10.1.0-milestone13"
},
{
"introduced": "0"
},
{
"last_affected": "10.1.0-milestone14"
},
{
"introduced": "0"
},
{
"last_affected": "10.1.0-milestone15"
},
{
"introduced": "0"
},
{
"last_affected": "10.1.0-milestone16"
},
{
"introduced": "0"
},
{
"last_affected": "10.1.0-milestone2"
},
{
"introduced": "0"
},
{
"last_affected": "10.1.0-milestone3"
},
{
"introduced": "0"
},
{
"last_affected": "10.1.0-milestone4"
},
{
"introduced": "0"
},
{
"last_affected": "10.1.0-milestone5"
},
{
"introduced": "0"
},
{
"last_affected": "10.1.0-milestone6"
},
{
"introduced": "0"
},
{
"last_affected": "10.1.0-milestone7"
},
{
"introduced": "0"
},
{
"last_affected": "10.1.0-milestone8"
},
{
"introduced": "0"
},
{
"last_affected": "10.1.0-milestone9"
}
]
}