Skip to content

[GHSA-f632-9449-3j4w] Apache Tomcat - XSS in generated JSPs#7668

Open
aruneko wants to merge 2 commits into
aruneko/advisory-improvement-7668from
aruneko-GHSA-f632-9449-3j4w
Open

[GHSA-f632-9449-3j4w] Apache Tomcat - XSS in generated JSPs#7668
aruneko wants to merge 2 commits into
aruneko/advisory-improvement-7668from
aruneko-GHSA-f632-9449-3j4w

Conversation

@aruneko

@aruneko aruneko commented May 12, 2026

Copy link
Copy Markdown
Contributor

Updates

  • Affected products

Comments
improve affected packages

Copilot AI review requested due to automatic review settings May 12, 2026 07:37
@github-actions github-actions Bot changed the base branch from main to aruneko/advisory-improvement-7668 May 12, 2026 07:38

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Updates the GHSA-f632-9449-3j4w advisory metadata to better enumerate affected Maven coordinates for the Apache Tomcat XSS issue, improving package matching for consumers of the advisory database.

Changes:

  • Expanded the affected list to include additional Tomcat-related Maven artifacts (org.apache.tomcat:tomcat and org.apache.tomcat.embed:tomcat-embed-jasper) across the impacted versions.
  • Updated the advisory modified timestamp.

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

@github-actions

Copy link
Copy Markdown

👋 This pull request has been marked as stale because it has been open with no activity. You can: comment on the issue or remove the stale label to hold stale off for a while, add the Keep label to hold stale off permanently, or do nothing. If you do nothing this pull request will be closed eventually by the stale bot. Please see CONTRIBUTING.md for more policy details.

@github-actions github-actions Bot added the Stale label Jun 13, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants