{"id":"CVE-2022-29885","details":"The documentation of Apache Tomcat 10.1.0-M1 to 10.1.0-M14, 10.0.0-M1 to 10.0.20, 9.0.13 to 9.0.62 and 8.5.38 to 8.5.78 for the EncryptInterceptor incorrectly stated it enabled Tomcat clustering to run over an untrusted network. This was not correct. While the EncryptInterceptor does provide confidentiality and integrity protection, it does not protect against all risks associated with running over any untrusted network, particularly DoS risks.","aliases":["BIT-tomcat-2022-29885","GHSA-r84p-88g2-2vx2"],"modified":"2026-04-10T04:47:24.768173Z","published":"2022-05-12T08:15:07.630Z","related":["MGASA-2023-0138"],"references":[{"type":"WEB","url":"http://packetstormsecurity.com/files/171728/Apache-Tomcat-10.1-Denial-Of-Service.html"},{"type":"ADVISORY","url":"https://security.netapp.com/advisory/ntap-20220629-0002/"},{"type":"ADVISORY","url":"https://www.debian.org/security/2022/dsa-5265"},{"type":"ADVISORY","url":"https://lists.apache.org/thread/2b4qmhbcyqvc7dyfpjyx54c03x65vhcv"},{"type":"ADVISORY","url":"https://lists.debian.org/debian-lts-announce/2022/10/msg00029.html"},{"type":"FIX","url":"https://www.oracle.com/security-alerts/cpujul2022.html"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/apache/tomcat","events":[{"introduced":"4b0b2f6b828d12d150b4de0b64fd6c3849dfcefb"},{"last_affected":"f732d3aa5ca55eb07cb73d9ec2b585330f80f00b"},{"introduced":"706a395be7c34414d04739de69bde986661976ec"},{"last_affected":"85113741042dcce9e9792bdbc3d498172bc31291"},{"introduced":"4c8b650437e2464c1c31c6598a263b3805b7a81f"},{"last_affected":"2a46c651529a9d237b4d6beb1ef846922d949342"},{"introduced":"0"},{"last_affected":"f2ab9ac8bc3f40ee9b2cb50b030c99df927f0429"},{"introduced":"0"},{"last_affected":"dc3639dd7123301ced18dbf4ddf2dca93704870d"},{"introduced":"0"},{"last_affected":"049799677ba307378a256621bb1a7b03f597571c"},{"introduced":"0"},{"last_affected":"d08498a3cefa7206bad791acf019455794f865ea"},{"introduced":"0"},{"last_affected":"faa2582152d9dcbcb444700df340e10a85fc375f"},{"introduced":"0"},{"last_affected":"02e84c839def0228475fad85d0b19abc2f70b03f"},{"introduced":"0"},{"last_affected":"0e59fedb28df646930c5aff945159b64d7a52260"},{"introduced":"0"},{"last_affected":"8778a44d6323c1066237043a89ab2f36696916b1"},{"introduced":"0"},{"last_affected":"e706972942e2c342e4a37baf5e2596f11e8a0e94"},{"introduced":"0"},{"last_affected":"2a10c8d9110d7b1c7f526f3352648c6b19ba2c52"},{"introduced":"0"},{"last_affected":"51d1031c36c0f2b3ee1e0d14b56228a559144153"},{"introduced":"0"},{"last_affected":"0f3f1e439a040068b741d77777766722e4420ad6"},{"introduced":"0"},{"last_affected":"cd53876fefaa370c31466b0f615e9ad026541a27"},{"introduced":"0"},{"last_affected":"02d546ba3c553c74ff1a99ecc166a6ff9c501ba8"},{"introduced":"0"},{"last_affected":"4c8b650437e2464c1c31c6598a263b3805b7a81f"},{"introduced":"0"},{"last_affected":"56e547d387ab49f688c93fe9ca082b1b5d94deed"}],"database_specific":{"versions":[{"introduced":"8.5.38"},{"last_affected":"8.5.78"},{"introduced":"9.0.13"},{"last_affected":"9.0.62"},{"introduced":"10.0.0"},{"last_affected":"10.0.20"},{"introduced":"0"},{"last_affected":"10.1.0-milestone1"},{"introduced":"0"},{"last_affected":"10.1.0-milestone10"},{"introduced":"0"},{"last_affected":"10.1.0-milestone11"},{"introduced":"0"},{"last_affected":"10.1.0-milestone12"},{"introduced":"0"},{"last_affected":"10.1.0-milestone13"},{"introduced":"0"},{"last_affected":"10.1.0-milestone14"},{"introduced":"0"},{"last_affected":"10.1.0-milestone2"},{"introduced":"0"},{"last_affected":"10.1.0-milestone3"},{"introduced":"0"},{"last_affected":"10.1.0-milestone4"},{"introduced":"0"},{"last_affected":"10.1.0-milestone5"},{"introduced":"0"},{"last_affected":"10.1.0-milestone6"},{"introduced":"0"},{"last_affected":"10.1.0-milestone7"},{"introduced":"0"},{"last_affected":"10.1.0-milestone8"},{"introduced":"0"},{"last_affected":"10.1.0-milestone9"},{"introduced":"0"},{"last_affected":"10.0"},{"introduced":"0"},{"last_affected":"11.0"}]}}],"versions":["10.0.0","10.0.20","10.1.0-M1","10.1.0-M10","10.1.0-M11","10.1.0-M12","10.1.0-M13","10.1.0-M14","10.1.0-M2","10.1.0-M3","10.1.0-M4","10.1.0-M5","10.1.0-M6","10.1.0-M7","10.1.0-M8","10.1.0-M9","11.0.0","8.5.78","9.0.62"],"database_specific":{"unresolved_ranges":[{"events":[{"introduced":"0"},{"last_affected":"20.2.1"}]}],"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-29885.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}