[GHSA-x4m4-345f-5h5g] Apache Tomcat vulnerable to Insertion of Sensitive Information into Log File#7652
Conversation
There was a problem hiding this comment.
Pull request overview
Updates the GitHub-reviewed OSV advisory for GHSA-x4m4-345f-5h5g / CVE-2026-34487 (Apache Tomcat sensitive info logged via clustering “cloud membership”) to better reflect the actually affected Maven artifacts.
Changes:
- Switch affected Maven artifact entries from
org.apache.tomcat:tomcat-catalinatoorg.apache.tomcat:tomcat-tribes. - Remove affected entries for
org.apache.tomcat.embed:tomcat-embed-corefor this advisory. - Minor bump to the advisory
modifiedtimestamp.
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
|
👋 This pull request has been marked as stale because it has been open with no activity. You can: comment on the issue or remove the stale label to hold stale off for a while, add the |
|
How is the status of a review for this pull request? |
Updates
Comments
improve affected packages