[
https://issues.apache.org/jira/browse/TOMEE-4677?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=18109856#comment-18109856
]
Richard Zowalla commented on TOMEE-4677:
----------------------------------------
Hi all,
we are usually aware of such updates (including the assosciated CVEs) -
dependabot runs against our code base and dependency upgrades are typically
picked up before a release anyway.
As is usual for ASF projects, there is no explicit roadmap or fixed date for
10.3.0. A release happens when a volunteer finds the time to prepare and drive
one.
Please also keep in mind that maintainer capacity is currently largely bound by
unsolicited, automated LLM-based scanning of the foundation's code bases.
Triaging those reports consumes time that is then no longer available for
development or release work.
Gruß
Richard
> Upgrade tomcat to 10.1.59
> -------------------------
>
> Key: TOMEE-4677
> URL: https://issues.apache.org/jira/browse/TOMEE-4677
> Project: TomEE
> Issue Type: Dependency upgrade
> Components: TomEE Core Server
> Affects Versions: 10.2.0
> Reporter: RAJU THANNEERU
> Priority: Major
> Fix For: 10.3.0
>
> Time Spent: 20m
> Remaining Estimate: 0h
>
> |[CVE-2026-66299|https://nvd.nist.gov/vuln/detail/CVE-2026-66299]|7.5|high|fixed
> in 11.0.25, 10.1.58, 9.0.121|2026-08-06 09:29:28 +0000
> UTC|[tomcat-util_10.1.57|http://10.96.74.60:6066/gitlab-ui/api/projects/131760/html-report?artifact=twistlock-appworks.html#sha256:605259df88676786462dc8161fa3b454c4079a314fc27b916b9a2e604863155c_tomcat-util_10.1.57]|this
> image|/usr/local/tomee/lib/tomcat-util.jar|
--
This message was sent by Atlassian Jira
(v8.20.10#820010)