[
https://issues.apache.org/jira/browse/TOMEE-4677?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=18109831#comment-18109831
]
RAJU THANNEERU commented on TOMEE-4677:
---------------------------------------
[HiĀ |https://github.com/apache/tomee/pull/2906] [Markus
Jung|https://github.com/apache/tomee/pull/2906], we see multiple criticals and
highs in tomcat.
Here is the PR link, hope you can check and merge it.
[https://github.com/apache/tomee/pull/2906]
|[CVE-2026-65182|https://nvd.nist.gov/vuln/detail/CVE-2026-65182]|9.1|critical|fixed
in 11.0.25, 10.1.58, 9.0.121,...|2026-08-27 21:20:54 +0000
UTC|[tomcat-util_10.1.57|https://otscan.otxlab.net/api/v1/scan/f80a9ecd-52e6-42ca-8a35-96da69735bd8/report/html#sha256:9418ad24b7255e35ae98da78cc1f3d2c51feb9163f24e1bc7db6c22485da2ce6_tomcat-util_10.1.57]|this
image|/usr/local/tomee/lib/tomcat-util.jar|
|[CVE-2026-65637|https://nvd.nist.gov/vuln/detail/CVE-2026-65637]|9.8|critical|fixed
in 11.0.25, 10.1.58, 9.0.121|2026-08-27 21:20:54 +0000
UTC|[tomcat-util_10.1.57|https://otscan.otxlab.net/api/v1/scan/f80a9ecd-52e6-42ca-8a35-96da69735bd8/report/html#sha256:9418ad24b7255e35ae98da78cc1f3d2c51feb9163f24e1bc7db6c22485da2ce6_tomcat-util_10.1.57]|this
image|/usr/local/tomee/lib/tomcat-util.jar|
|[CVE-2026-65905|https://nvd.nist.gov/vuln/detail/CVE-2026-65905]|9.8|critical|fixed
in 11.0.25, 10.1.58, 9.0.121,...|2026-08-27 21:20:54 +0000
UTC|[tomcat-util_10.1.57|https://otscan.otxlab.net/api/v1/scan/f80a9ecd-52e6-42ca-8a35-96da69735bd8/report/html#sha256:9418ad24b7255e35ae98da78cc1f3d2c51feb9163f24e1bc7db6c22485da2ce6_tomcat-util_10.1.57]|this
image|/usr/local/tomee/lib/tomcat-util.jar|
|[CVE-2026-68525|https://nvd.nist.gov/vuln/detail/CVE-2026-68525]|9.1|critical|fixed
in 11.0.25, 10.1.58, 9.0.121,...|2026-08-27 21:20:54 +0000
UTC|[tomcat-util_10.1.57|https://otscan.otxlab.net/api/v1/scan/f80a9ecd-52e6-42ca-8a35-96da69735bd8/report/html#sha256:9418ad24b7255e35ae98da78cc1f3d2c51feb9163f24e1bc7db6c22485da2ce6_tomcat-util_10.1.57]|this
image|/usr/local/tomee/lib/tomcat-util.jar|
|[CVE-2026-65183|https://nvd.nist.gov/vuln/detail/CVE-2026-65183]|8.1|high|fixed
in 11.0.25, 10.1.58, 9.0.121|2026-08-27 21:20:54 +0000
UTC|[tomcat-util_10.1.57|https://otscan.otxlab.net/api/v1/scan/f80a9ecd-52e6-42ca-8a35-96da69735bd8/report/html#sha256:9418ad24b7255e35ae98da78cc1f3d2c51feb9163f24e1bc7db6c22485da2ce6_tomcat-util_10.1.57]|this
image|/usr/local/tomee/lib/tomcat-util.jar|
|[CVE-2026-65927|https://nvd.nist.gov/vuln/detail/CVE-2026-65927]|7.5|high|fixed
in 11.0.25, 10.1.58, 9.0.121|2026-08-27 21:20:54 +0000
UTC|[tomcat-util_10.1.57|https://otscan.otxlab.net/api/v1/scan/f80a9ecd-52e6-42ca-8a35-96da69735bd8/report/html#sha256:9418ad24b7255e35ae98da78cc1f3d2c51feb9163f24e1bc7db6c22485da2ce6_tomcat-util_10.1.57]|this
image|/usr/local/tomee/lib/tomcat-util.jar|
|[CVE-2026-66422|https://nvd.nist.gov/vuln/detail/CVE-2026-66422]|8.1|high|fixed
in 11.0.25, 10.1.58, 9.0.121,...|2026-08-27 21:20:54 +0000
UTC|[tomcat-util_10.1.57|https://otscan.otxlab.net/api/v1/scan/f80a9ecd-52e6-42ca-8a35-96da69735bd8/report/html#sha256:9418ad24b7255e35ae98da78cc1f3d2c51feb9163f24e1bc7db6c22485da2ce6_tomcat-util_10.1.57]|this
image|/usr/local/tomee/lib/tomcat-util.jar|
|[CVE-2026-68569|https://nvd.nist.gov/vuln/detail/CVE-2026-68569]|8.1|high|fixed
in 11.0.25, 10.1.58, 9.0.121,...|2026-08-27 21:20:54 +0000
UTC|[tomcat-util_10.1.57|https://otscan.otxlab.net/api/v1/scan/f80a9ecd-52e6-42ca-8a35-96da69735bd8/report/html#sha256:9418ad24b7255e35ae98da78cc1f3d2c51feb9163f24e1bc7db6c22485da2ce6_tomcat-util_10.1.57]|this
image|/usr/local/tomee/lib/tomcat-util.jar|
|[CVE-2026-68763|https://nvd.nist.gov/vuln/detail/CVE-2026-68763]|7.5|high|fixed
in 11.0.25, 10.1.58, 9.0.121|2026-08-27 17:28:44 +0000
UTC|[tomcat-util_10.1.57|https://otscan.otxlab.net/api/v1/scan/f80a9ecd-52e6-42ca-8a35-96da69735bd8/report/html#sha256:9418ad24b7255e35ae98da78cc1f3d2c51feb9163f24e1bc7db6c22485da2ce6_tomcat-util_10.1.57]|this
image|/usr/local/tomee/lib/tomcat-util.jar|
|[CVE-2026-66299|https://nvd.nist.gov/vuln/detail/CVE-2026-66299]|5.3|medium|fixed
in 11.0.25, 10.1.58, 9.0.121|2026-08-06 09:29:28 +0000
UTC|[tomcat-util_10.1.57|https://otscan.otxlab.net/api/v1/scan/f80a9ecd-52e6-42ca-8a35-96da69735bd8/report/html#sha256:9418ad24b7255e35ae98da78cc1f3d2c51feb9163f24e1bc7db6c22485da2ce6_tomcat-util_10.1.57]|this
image|/usr/local/tomee/lib/tomcat-util.jar|
|[CVE-2026-73180|https://nvd.nist.gov/vuln/detail/CVE-2026-73180]|6.8|medium|fixed
in 11.0.25, 10.1.58, 9.0.121,...|2026-08-27 17:28:44 +0000
UTC|[tomcat-util_10.1.57|https://otscan.otxlab.net/api/v1/scan/f80a9ecd-52e6-42ca-8a35-96da69735bd8/report/html#sha256:9418ad24b7255e35ae98da78cc1f3d2c51feb9163f24e1bc7db6c22485da2ce6_tomcat-util_10.1.57]|this
image|/usr/local/tomee/lib/tomcat-util.jar|
> Upgrade tomcat to 10.1.59
> -------------------------
>
> Key: TOMEE-4677
> URL: https://issues.apache.org/jira/browse/TOMEE-4677
> Project: TomEE
> Issue Type: Dependency upgrade
> Components: TomEE Core Server
> Affects Versions: 10.2.0
> Reporter: RAJU THANNEERU
> Priority: Major
> Fix For: 10.3.0
>
> Time Spent: 10m
> Remaining Estimate: 0h
>
> |[CVE-2026-66299|https://nvd.nist.gov/vuln/detail/CVE-2026-66299]|7.5|high|fixed
> in 11.0.25, 10.1.58, 9.0.121|2026-08-06 09:29:28 +0000
> UTC|[tomcat-util_10.1.57|http://10.96.74.60:6066/gitlab-ui/api/projects/131760/html-report?artifact=twistlock-appworks.html#sha256:605259df88676786462dc8161fa3b454c4079a314fc27b916b9a2e604863155c_tomcat-util_10.1.57]|this
> image|/usr/local/tomee/lib/tomcat-util.jar|
--
This message was sent by Atlassian Jira
(v8.20.10#820010)