[
https://issues.apache.org/jira/browse/TOMEE-4676?focusedWorklogId=1038759&page=com.atlassian.jira.plugin.system.issuetabpanels:worklog-tabpanel#worklog-1038759
]
ASF GitHub Bot logged work on TOMEE-4676:
-----------------------------------------
Author: ASF GitHub Bot
Created on: 31/Aug/26 09:46
Start Date: 31/Aug/26 09:46
Worklog Time Spent: 10m
Work Description: raju74400 opened a new pull request, #2907:
URL: https://github.com/apache/tomee/pull/2907
(no comment)
Issue Time Tracking
-------------------
Worklog Id: (was: 1038759)
Remaining Estimate: 0h
Time Spent: 10m
> Upgrade CXF
> -----------
>
> Key: TOMEE-4676
> URL: https://issues.apache.org/jira/browse/TOMEE-4676
> Project: TomEE
> Issue Type: Dependency upgrade
> Components: TomEE Core Server
> Affects Versions: 10.2.0
> Reporter: RAJU THANNEERU
> Priority: Major
> Fix For: 10.3.0
>
> Time Spent: 10m
> Remaining Estimate: 0h
>
> Critical and high severity issues in CXF
> |[CVE-2026-61466|https://nvd.nist.gov/vuln/detail/CVE-2026-61466]|9.1|critical|fixed
> in 4.2.3, 4.1.8, 3.6.12|2026-08-07 05:23:22 +0000
> UTC|[org.apache.cxf_cxf-core_4.1.7|http://10.96.74.60:6066/gitlab-ui/api/projects/131760/html-report?artifact=twistlock-appworks.html#sha256:605259df88676786462dc8161fa3b454c4079a314fc27b916b9a2e604863155c_org.apache.cxf_cxf-core_4.1.7]|this
> image|/usr/local/tomee/lib/cxf-core-4.1.7.jar|
> |[CVE-2026-63687|https://nvd.nist.gov/vuln/detail/CVE-2026-63687]|9.1|critical|fixed
> in 4.2.3, 4.1.8, 3.6.12|2026-08-07 05:23:22 +0000
> UTC|[org.apache.cxf_cxf-core_4.1.7|http://10.96.74.60:6066/gitlab-ui/api/projects/131760/html-report?artifact=twistlock-appworks.html#sha256:605259df88676786462dc8161fa3b454c4079a314fc27b916b9a2e604863155c_org.apache.cxf_cxf-core_4.1.7]|this
> image|/usr/local/tomee/lib/cxf-core-4.1.7.jar|
> |[CVE-2026-65583|https://nvd.nist.gov/vuln/detail/CVE-2026-65583]|9.1|critical|fixed
> in 4.2.3, 4.1.8, 3.6.12|2026-08-07 05:23:22 +0000
> UTC|[org.apache.cxf_cxf-core_4.1.7|http://10.96.74.60:6066/gitlab-ui/api/projects/131760/html-report?artifact=twistlock-appworks.html#sha256:605259df88676786462dc8161fa3b454c4079a314fc27b916b9a2e604863155c_org.apache.cxf_cxf-core_4.1.7]|this
> image|/usr/local/tomee/lib/cxf-core-4.1.7.jar|
> |[CVE-2026-66909|https://nvd.nist.gov/vuln/detail/CVE-2026-66909]|9.8|critical|fixed
> in 4.2.3, 4.1.8, 3.6.12|2026-08-07 05:23:22 +0000
> UTC|[org.apache.cxf_cxf-core_4.1.7|http://10.96.74.60:6066/gitlab-ui/api/projects/131760/html-report?artifact=twistlock-appworks.html#sha256:605259df88676786462dc8161fa3b454c4079a314fc27b916b9a2e604863155c_org.apache.cxf_cxf-core_4.1.7]|this
> image|/usr/local/tomee/lib/cxf-core-4.1.7.jar|
> |[CVE-2026-68079|https://nvd.nist.gov/vuln/detail/CVE-2026-68079]|9.8|critical|fixed
> in 4.2.3, 4.1.8, 3.6.12|2026-08-07 05:23:22 +0000
> UTC|[org.apache.cxf_cxf-core_4.1.7|http://10.96.74.60:6066/gitlab-ui/api/projects/131760/html-report?artifact=twistlock-appworks.html#sha256:605259df88676786462dc8161fa3b454c4079a314fc27b916b9a2e604863155c_org.apache.cxf_cxf-core_4.1.7]|this
> image|/usr/local/tomee/lib/cxf-core-4.1.7.jar|
> |[CVE-2026-54225|https://nvd.nist.gov/vuln/detail/CVE-2026-54225]|7.5|high|fixed
> in 4.2.3, 4.1.8, 3.6.12|2026-08-07 05:23:22 +0000
> UTC|[org.apache.cxf_cxf-core_4.1.7|http://10.96.74.60:6066/gitlab-ui/api/projects/131760/html-report?artifact=twistlock-appworks.html#sha256:605259df88676786462dc8161fa3b454c4079a314fc27b916b9a2e604863155c_org.apache.cxf_cxf-core_4.1.7]|this
> image|/usr/local/tomee/lib/cxf-core-4.1.7.jar|
> |[CVE-2026-57817|https://nvd.nist.gov/vuln/detail/CVE-2026-57817]|8.1|high|fixed
> in 4.2.3, 4.1.8, 3.6.12|2026-08-07 05:23:22 +0000
> UTC|[org.apache.cxf_cxf-core_4.1.7|http://10.96.74.60:6066/gitlab-ui/api/projects/131760/html-report?artifact=twistlock-appworks.html#sha256:605259df88676786462dc8161fa3b454c4079a314fc27b916b9a2e604863155c_org.apache.cxf_cxf-core_4.1.7]|this
> image|/usr/local/tomee/lib/cxf-core-4.1.7.jar|
> |[CVE-2026-57818|https://nvd.nist.gov/vuln/detail/CVE-2026-57818]|8.1|high|fixed
> in 4.2.3, 4.1.8, 3.6.12|2026-08-07 05:23:22 +0000
> UTC|[org.apache.cxf_cxf-core_4.1.7|http://10.96.74.60:6066/gitlab-ui/api/projects/131760/html-report?artifact=twistlock-appworks.html#sha256:605259df88676786462dc8161fa3b454c4079a314fc27b916b9a2e604863155c_org.apache.cxf_cxf-core_4.1.7]|this
> image|/usr/local/tomee/lib/cxf-core-4.1.7.jar|
> |[CVE-2026-57819|https://nvd.nist.gov/vuln/detail/CVE-2026-57819]|7.5|high|fixed
> in 4.2.3, 4.1.8, 3.6.12|2026-08-07 05:23:22 +0000
> UTC|[org.apache.cxf_cxf-core_4.1.7|http://10.96.74.60:6066/gitlab-ui/api/projects/131760/html-report?artifact=twistlock-appworks.html#sha256:605259df88676786462dc8161fa3b454c4079a314fc27b916b9a2e604863155c_org.apache.cxf_cxf-core_4.1.7]|this
> image|/usr/local/tomee/lib/cxf-core-4.1.7.jar|
> |[CVE-2026-64958|https://nvd.nist.gov/vuln/detail/CVE-2026-64958]|7.5|high|fixed
> in 4.2.3, 4.1.8, 3.6.12|2026-08-07 05:23:22 +0000
> UTC|[org.apache.cxf_cxf-core_4.1.7|http://10.96.74.60:6066/gitlab-ui/api/projects/131760/html-report?artifact=twistlock-appworks.html#sha256:605259df88676786462dc8161fa3b454c4079a314fc27b916b9a2e604863155c_org.apache.cxf_cxf-core_4.1.7]|this
> image|/usr/local/tomee/lib/cxf-core-4.1.7.jar|
> |[CVE-2026-65432|https://nvd.nist.gov/vuln/detail/CVE-2026-65432]|7.5|high|fixed
> in 4.2.3, 4.1.8, 3.6.12|2026-08-07 05:23:22 +0000
> UTC|[org.apache.cxf_cxf-core_4.1.7|http://10.96.74.60:6066/gitlab-ui/api/projects/131760/html-report?artifact=twistlock-appworks.html#sha256:605259df88676786462dc8161fa3b454c4079a314fc27b916b9a2e604863155c_org.apache.cxf_cxf-core_4.1.7]|this
> image|/usr/local/tomee/lib/cxf-core-4.1.7.jar|
> |[CVE-2026-68481|https://nvd.nist.gov/vuln/detail/CVE-2026-68481]|7.5|high|fixed
> in 4.2.3, 4.1.8, 3.6.12|2026-08-07 05:23:22 +0000
> UTC|[org.apache.cxf_cxf-core_4.1.7|http://10.96.74.60:6066/gitlab-ui/api/projects/131760/html-report?artifact=twistlock-appworks.html#sha256:605259df88676786462dc8161fa3b454c4079a314fc27b916b9a2e604863155c_org.apache.cxf_cxf-core_4.1.7]|this
> image|/usr/local/tomee/lib/cxf-core-4.1.7.jar|
--
This message was sent by Atlassian Jira
(v8.20.10#820010)