Skip to content

[GHSA-f4qf-m5gf-8jm8] Apache Tomcat vulnerable to Generation of Error Message Containing Sensitive Information#7656

Merged
advisory-database[bot] merged 1 commit into
aruneko/advisory-improvement-7656from
aruneko-GHSA-f4qf-m5gf-8jm8
Jun 18, 2026
Merged

[GHSA-f4qf-m5gf-8jm8] Apache Tomcat vulnerable to Generation of Error Message Containing Sensitive Information#7656
advisory-database[bot] merged 1 commit into
aruneko/advisory-improvement-7656from
aruneko-GHSA-f4qf-m5gf-8jm8

Conversation

@aruneko

@aruneko aruneko commented May 12, 2026

Copy link
Copy Markdown
Contributor

Updates

  • Affected products

Comments
improve affected packages

Copilot AI review requested due to automatic review settings May 12, 2026 01:37
@github-actions github-actions Bot changed the base branch from main to aruneko/advisory-improvement-7656 May 12, 2026 01:38

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Updates the GHSA advisory entry for CVE-2024-21733 (Apache Tomcat “Generation of Error Message Containing Sensitive Information”) to more accurately represent affected Maven artifacts and version ranges in the advisory database.

Changes:

  • Expanded the affected list to include additional relevant Maven coordinates (Tomcat embed artifacts and an experimental embed module).
  • Added explicit affected version ranges for the 8.5.x and 9.0.x lines where applicable.
  • Bumped the advisory modified timestamp.

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

@github-actions

Copy link
Copy Markdown

👋 This pull request has been marked as stale because it has been open with no activity. You can: comment on the issue or remove the stale label to hold stale off for a while, add the Keep label to hold stale off permanently, or do nothing. If you do nothing this pull request will be closed eventually by the stale bot. Please see CONTRIBUTING.md for more policy details.

@github-actions github-actions Bot added the Stale label Jun 10, 2026
@aruneko

aruneko commented Jun 11, 2026

Copy link
Copy Markdown
Contributor Author

How is the status of a review for this pull request?

@JonathanLEvans

Copy link
Copy Markdown

Hi @aruneko,

Could you show us how you determined that the versions of org.apache.tomcat.experimental:tomcat-embed-programmatic are affected.

@github-actions github-actions Bot removed the Stale label Jun 12, 2026
@aruneko

aruneko commented Jun 12, 2026

Copy link
Copy Markdown
Contributor Author

Hello, thank you for your confirmation.

In fact, org.apache.tomcat.experimental:tomcat-embed-programmatic contains org.apache.tomcat:tomcat-coyote. That's why, I added the package as an affected.

@advisory-database advisory-database Bot merged commit f0a4e8c into aruneko/advisory-improvement-7656 Jun 18, 2026
7 of 8 checks passed
@advisory-database

Copy link
Copy Markdown
Contributor

Hi @aruneko! Thank you so much for contributing to the GitHub Advisory Database. This database is free, open, and accessible to all, and it's people like you who make it great. Thanks for choosing to help others. We hope you send in more contributions in the future!

@advisory-database advisory-database Bot deleted the aruneko-GHSA-f4qf-m5gf-8jm8 branch June 18, 2026 23:16
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants