[
https://issues.apache.org/jira/browse/TOMEE-4676?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=18103910#comment-18103910
]
RAJU THANNEERU edited comment on TOMEE-4676 at 8/14/26 10:01 AM:
-----------------------------------------------------------------
Hi [~jungm], can this be included in the 10.3.0? As we see multiple critical
and high issues.
was (Author: JIRAUSER296575):
Hi [~mjung], can this be included in the 10.3.0? As we see multiple critical
and high issues.
> Upgrade CXF
> -----------
>
> Key: TOMEE-4676
> URL: https://issues.apache.org/jira/browse/TOMEE-4676
> Project: TomEE
> Issue Type: Dependency upgrade
> Components: TomEE Core Server
> Affects Versions: 10.2.0
> Reporter: RAJU THANNEERU
> Priority: Major
> Fix For: 10.3.0
>
>
> Critical and high severity issues in CXF
> |[CVE-2026-61466|https://nvd.nist.gov/vuln/detail/CVE-2026-61466]|9.1|critical|fixed
> in 4.2.3, 4.1.8, 3.6.12|2026-08-07 05:23:22 +0000
> UTC|[org.apache.cxf_cxf-core_4.1.7|http://10.96.74.60:6066/gitlab-ui/api/projects/131760/html-report?artifact=twistlock-appworks.html#sha256:605259df88676786462dc8161fa3b454c4079a314fc27b916b9a2e604863155c_org.apache.cxf_cxf-core_4.1.7]|this
> image|/usr/local/tomee/lib/cxf-core-4.1.7.jar|
> |[CVE-2026-63687|https://nvd.nist.gov/vuln/detail/CVE-2026-63687]|9.1|critical|fixed
> in 4.2.3, 4.1.8, 3.6.12|2026-08-07 05:23:22 +0000
> UTC|[org.apache.cxf_cxf-core_4.1.7|http://10.96.74.60:6066/gitlab-ui/api/projects/131760/html-report?artifact=twistlock-appworks.html#sha256:605259df88676786462dc8161fa3b454c4079a314fc27b916b9a2e604863155c_org.apache.cxf_cxf-core_4.1.7]|this
> image|/usr/local/tomee/lib/cxf-core-4.1.7.jar|
> |[CVE-2026-65583|https://nvd.nist.gov/vuln/detail/CVE-2026-65583]|9.1|critical|fixed
> in 4.2.3, 4.1.8, 3.6.12|2026-08-07 05:23:22 +0000
> UTC|[org.apache.cxf_cxf-core_4.1.7|http://10.96.74.60:6066/gitlab-ui/api/projects/131760/html-report?artifact=twistlock-appworks.html#sha256:605259df88676786462dc8161fa3b454c4079a314fc27b916b9a2e604863155c_org.apache.cxf_cxf-core_4.1.7]|this
> image|/usr/local/tomee/lib/cxf-core-4.1.7.jar|
> |[CVE-2026-66909|https://nvd.nist.gov/vuln/detail/CVE-2026-66909]|9.8|critical|fixed
> in 4.2.3, 4.1.8, 3.6.12|2026-08-07 05:23:22 +0000
> UTC|[org.apache.cxf_cxf-core_4.1.7|http://10.96.74.60:6066/gitlab-ui/api/projects/131760/html-report?artifact=twistlock-appworks.html#sha256:605259df88676786462dc8161fa3b454c4079a314fc27b916b9a2e604863155c_org.apache.cxf_cxf-core_4.1.7]|this
> image|/usr/local/tomee/lib/cxf-core-4.1.7.jar|
> |[CVE-2026-68079|https://nvd.nist.gov/vuln/detail/CVE-2026-68079]|9.8|critical|fixed
> in 4.2.3, 4.1.8, 3.6.12|2026-08-07 05:23:22 +0000
> UTC|[org.apache.cxf_cxf-core_4.1.7|http://10.96.74.60:6066/gitlab-ui/api/projects/131760/html-report?artifact=twistlock-appworks.html#sha256:605259df88676786462dc8161fa3b454c4079a314fc27b916b9a2e604863155c_org.apache.cxf_cxf-core_4.1.7]|this
> image|/usr/local/tomee/lib/cxf-core-4.1.7.jar|
> |[CVE-2026-54225|https://nvd.nist.gov/vuln/detail/CVE-2026-54225]|7.5|high|fixed
> in 4.2.3, 4.1.8, 3.6.12|2026-08-07 05:23:22 +0000
> UTC|[org.apache.cxf_cxf-core_4.1.7|http://10.96.74.60:6066/gitlab-ui/api/projects/131760/html-report?artifact=twistlock-appworks.html#sha256:605259df88676786462dc8161fa3b454c4079a314fc27b916b9a2e604863155c_org.apache.cxf_cxf-core_4.1.7]|this
> image|/usr/local/tomee/lib/cxf-core-4.1.7.jar|
> |[CVE-2026-57817|https://nvd.nist.gov/vuln/detail/CVE-2026-57817]|8.1|high|fixed
> in 4.2.3, 4.1.8, 3.6.12|2026-08-07 05:23:22 +0000
> UTC|[org.apache.cxf_cxf-core_4.1.7|http://10.96.74.60:6066/gitlab-ui/api/projects/131760/html-report?artifact=twistlock-appworks.html#sha256:605259df88676786462dc8161fa3b454c4079a314fc27b916b9a2e604863155c_org.apache.cxf_cxf-core_4.1.7]|this
> image|/usr/local/tomee/lib/cxf-core-4.1.7.jar|
> |[CVE-2026-57818|https://nvd.nist.gov/vuln/detail/CVE-2026-57818]|8.1|high|fixed
> in 4.2.3, 4.1.8, 3.6.12|2026-08-07 05:23:22 +0000
> UTC|[org.apache.cxf_cxf-core_4.1.7|http://10.96.74.60:6066/gitlab-ui/api/projects/131760/html-report?artifact=twistlock-appworks.html#sha256:605259df88676786462dc8161fa3b454c4079a314fc27b916b9a2e604863155c_org.apache.cxf_cxf-core_4.1.7]|this
> image|/usr/local/tomee/lib/cxf-core-4.1.7.jar|
> |[CVE-2026-57819|https://nvd.nist.gov/vuln/detail/CVE-2026-57819]|7.5|high|fixed
> in 4.2.3, 4.1.8, 3.6.12|2026-08-07 05:23:22 +0000
> UTC|[org.apache.cxf_cxf-core_4.1.7|http://10.96.74.60:6066/gitlab-ui/api/projects/131760/html-report?artifact=twistlock-appworks.html#sha256:605259df88676786462dc8161fa3b454c4079a314fc27b916b9a2e604863155c_org.apache.cxf_cxf-core_4.1.7]|this
> image|/usr/local/tomee/lib/cxf-core-4.1.7.jar|
> |[CVE-2026-64958|https://nvd.nist.gov/vuln/detail/CVE-2026-64958]|7.5|high|fixed
> in 4.2.3, 4.1.8, 3.6.12|2026-08-07 05:23:22 +0000
> UTC|[org.apache.cxf_cxf-core_4.1.7|http://10.96.74.60:6066/gitlab-ui/api/projects/131760/html-report?artifact=twistlock-appworks.html#sha256:605259df88676786462dc8161fa3b454c4079a314fc27b916b9a2e604863155c_org.apache.cxf_cxf-core_4.1.7]|this
> image|/usr/local/tomee/lib/cxf-core-4.1.7.jar|
> |[CVE-2026-65432|https://nvd.nist.gov/vuln/detail/CVE-2026-65432]|7.5|high|fixed
> in 4.2.3, 4.1.8, 3.6.12|2026-08-07 05:23:22 +0000
> UTC|[org.apache.cxf_cxf-core_4.1.7|http://10.96.74.60:6066/gitlab-ui/api/projects/131760/html-report?artifact=twistlock-appworks.html#sha256:605259df88676786462dc8161fa3b454c4079a314fc27b916b9a2e604863155c_org.apache.cxf_cxf-core_4.1.7]|this
> image|/usr/local/tomee/lib/cxf-core-4.1.7.jar|
> |[CVE-2026-68481|https://nvd.nist.gov/vuln/detail/CVE-2026-68481]|7.5|high|fixed
> in 4.2.3, 4.1.8, 3.6.12|2026-08-07 05:23:22 +0000
> UTC|[org.apache.cxf_cxf-core_4.1.7|http://10.96.74.60:6066/gitlab-ui/api/projects/131760/html-report?artifact=twistlock-appworks.html#sha256:605259df88676786462dc8161fa3b454c4079a314fc27b916b9a2e604863155c_org.apache.cxf_cxf-core_4.1.7]|this
> image|/usr/local/tomee/lib/cxf-core-4.1.7.jar|
--
This message was sent by Atlassian Jira
(v8.20.10#820010)