[GHSA-f4qf-m5gf-8jm8] Apache Tomcat vulnerable to Generation of Error Message Containing Sensitive Information#7656
Conversation
There was a problem hiding this comment.
Pull request overview
Updates the GHSA advisory entry for CVE-2024-21733 (Apache Tomcat “Generation of Error Message Containing Sensitive Information”) to more accurately represent affected Maven artifacts and version ranges in the advisory database.
Changes:
- Expanded the
affectedlist to include additional relevant Maven coordinates (Tomcat embed artifacts and an experimental embed module). - Added explicit affected version ranges for the 8.5.x and 9.0.x lines where applicable.
- Bumped the advisory
modifiedtimestamp.
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
|
👋 This pull request has been marked as stale because it has been open with no activity. You can: comment on the issue or remove the stale label to hold stale off for a while, add the |
|
How is the status of a review for this pull request? |
|
Hi @aruneko, Could you show us how you determined that the versions of org.apache.tomcat.experimental:tomcat-embed-programmatic are affected. |
|
Hello, thank you for your confirmation. In fact, |
Updates
Comments
improve affected packages