Skip to content

[GHSA-f4qf-m5gf-8jm8] Apache Tomcat vulnerable to Generation of Error Message Containing Sensitive Information#7656

Open
aruneko wants to merge 1 commit into
aruneko/advisory-improvement-7656from
aruneko-GHSA-f4qf-m5gf-8jm8
Open

[GHSA-f4qf-m5gf-8jm8] Apache Tomcat vulnerable to Generation of Error Message Containing Sensitive Information#7656
aruneko wants to merge 1 commit into
aruneko/advisory-improvement-7656from
aruneko-GHSA-f4qf-m5gf-8jm8

Conversation

@aruneko

@aruneko aruneko commented May 12, 2026

Copy link
Copy Markdown
Contributor

Updates

  • Affected products

Comments
improve affected packages

Copilot AI review requested due to automatic review settings May 12, 2026 01:37
@github-actions github-actions Bot changed the base branch from main to aruneko/advisory-improvement-7656 May 12, 2026 01:38

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Updates the GHSA advisory entry for CVE-2024-21733 (Apache Tomcat “Generation of Error Message Containing Sensitive Information”) to more accurately represent affected Maven artifacts and version ranges in the advisory database.

Changes:

  • Expanded the affected list to include additional relevant Maven coordinates (Tomcat embed artifacts and an experimental embed module).
  • Added explicit affected version ranges for the 8.5.x and 9.0.x lines where applicable.
  • Bumped the advisory modified timestamp.

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

@github-actions

Copy link
Copy Markdown

👋 This pull request has been marked as stale because it has been open with no activity. You can: comment on the issue or remove the stale label to hold stale off for a while, add the Keep label to hold stale off permanently, or do nothing. If you do nothing this pull request will be closed eventually by the stale bot. Please see CONTRIBUTING.md for more policy details.

@github-actions github-actions Bot added the Stale label Jun 10, 2026
@aruneko

aruneko commented Jun 11, 2026

Copy link
Copy Markdown
Contributor Author

How is the status of a review for this pull request?

@JonathanLEvans

Copy link
Copy Markdown

Hi @aruneko,

Could you show us how you determined that the versions of org.apache.tomcat.experimental:tomcat-embed-programmatic are affected.

@github-actions github-actions Bot removed the Stale label Jun 12, 2026
@aruneko

aruneko commented Jun 12, 2026

Copy link
Copy Markdown
Contributor Author

Hello, thank you for your confirmation.

In fact, org.apache.tomcat.experimental:tomcat-embed-programmatic contains org.apache.tomcat:tomcat-coyote. That's why, I added the package as an affected.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants