Hi Tomcat Team, I have a question regarding the security vulnerabilities disclosed in the Tomcat 9.0.122 release.
The security page lists 12 issues (4 Important, 3 Moderate, and 5 Low severity). For each of these CVEs, the mitigation appears to be: Remove the examples web application However, when reviewing the commit links associated with the CVEs, the fixes appear to have been implemented in core Tomcat classes rather than solely within the examples application. Could you please clarify whether all 12 CVEs are only exploitable through the *examples* web application, and whether removing the examples application alone is sufficient to mitigate these vulnerabilities without upgrading Tomcat? Reference: https://tomcat.apache.org/security-9.html#Fixed_in_Apache_Tomcat_9.0.122 Thank you for your time and clarification. Kind regards, Thiru
