Skip to content

[GHSA-jjpq-gp5q-8q6w] Cross-site scripting in Apache Tomcat#7651

Closed
aruneko wants to merge 1 commit into
aruneko/advisory-improvement-7651from
aruneko-GHSA-jjpq-gp5q-8q6w
Closed

[GHSA-jjpq-gp5q-8q6w] Cross-site scripting in Apache Tomcat#7651
aruneko wants to merge 1 commit into
aruneko/advisory-improvement-7651from
aruneko-GHSA-jjpq-gp5q-8q6w

Conversation

@aruneko

@aruneko aruneko commented May 12, 2026

Copy link
Copy Markdown
Contributor

Updates

  • Affected products

Comments
improve affected packages

Copilot AI review requested due to automatic review settings May 12, 2026 01:11
@github-actions github-actions Bot changed the base branch from main to aruneko/advisory-improvement-7651 May 12, 2026 01:12

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR updates the OSV advisory for GHSA-jjpq-gp5q-8q6w / CVE-2019-0221 to broaden/clarify the set of affected Maven artifacts for Apache Tomcat.

Changes:

  • Adds affected version ranges for org.apache.tomcat:tomcat.
  • Adds affected version ranges for org.apache.tomcat:tomcat-catalina.
  • Updates the advisory modified timestamp.

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Comment on lines +84 to +89
{
"introduced": "9.0.0"
},
{
"fixed": "9.0.17"
}
Comment on lines +102 to +108
"events": [
{
"introduced": "8.0.0"
},
{
"fixed": "8.5.40"
}
Comment on lines +141 to +146
{
"introduced": "9.0.0"
},
{
"fixed": "9.0.17"
}
Comment on lines +159 to +165
"events": [
{
"introduced": "8.0.0"
},
{
"fixed": "8.5.40"
}
@aruneko aruneko closed this May 13, 2026
@github-actions github-actions Bot deleted the aruneko-GHSA-jjpq-gp5q-8q6w branch May 13, 2026 04:18
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants