High
CVE-2022-45143
Apache Tomcat could allow a remote attacker to bypass security restrictions, caused by not escape the type, message or description values in the JsonErrorReportValve function. By sending a specially-crafted request, an attacker could exploit this vulnerability to supply values that invalidated or manipulated the JSON output.
Apache
Upgrade to the latest version of Apache Tomcat, available from the Apache Website.