Skip to content

[GHSA-g8pj-r55q-5c2v] Apache Tomcat Incomplete Cleanup vulnerability#7666

Open
aruneko wants to merge 1 commit into
aruneko/advisory-improvement-7666from
aruneko-GHSA-g8pj-r55q-5c2v
Open

[GHSA-g8pj-r55q-5c2v] Apache Tomcat Incomplete Cleanup vulnerability#7666
aruneko wants to merge 1 commit into
aruneko/advisory-improvement-7666from
aruneko-GHSA-g8pj-r55q-5c2v

Conversation

@aruneko
Copy link
Copy Markdown

@aruneko aruneko commented May 12, 2026

Updates

  • Affected products

Comments
improve affected packages

Copilot AI review requested due to automatic review settings May 12, 2026 07:34
@github-actions github-actions Bot changed the base branch from main to aruneko/advisory-improvement-7666 May 12, 2026 07:35
Copy link
Copy Markdown
Contributor

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Updates the GitHub-reviewed advisory record for GHSA-g8pj-r55q-5c2v / CVE-2023-42795 (Apache Tomcat Incomplete Cleanup) by refining the Maven artifacts listed under affected, aligning the advisory’s package coverage with more specific Tomcat modules.

Changes:

  • Expanded/adjusted the affected package list to include additional Tomcat Maven artifacts (e.g., tomcat-embed-core, tomcat-catalina, tomcat-util) with explicit version ranges.
  • Updated the advisory modified timestamp.

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Comment on lines 17 to +40
"affected": [
{
"package": {
"ecosystem": "Maven",
"name": "org.apache.tomcat:tomcat-coyote"
"name": "org.apache.tomcat:tomcat"
},
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "9.0.0-M1"
},
{
"fixed": "9.0.81"
}
]
}
]
},
{
"package": {
"ecosystem": "Maven",
"name": "org.apache.tomcat:tomcat"
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants