On 9/26/26 04:27, Thiru wrote:
The security page lists 12 issues (4 Important, 3 Moderate, and 5 Low
severity). For each of these CVEs, the mitigation appears to be:
Remove the examples web application
[...]
Could you please clarify whether all 12 CVEs are only exploitable through
the *examples* web application, and whether removing the examples
application alone is sufficient to mitigate these vulnerabilities without
upgrading Tomcat?
Reference:
https://tomcat.apache.org/security-9.html#Fixed_in_Apache_Tomcat_9.0.122
Where do you see this? The only reference to removing the examples web
application I can find is in the CVE disclosure mails from Mark. The
"Remove the examples web application" started with his mail on July
28th, CVE-2026-66299, and continues in every other CVE disclosure. My
guess is that he simply forgot to remove the "Remove the examples web
application" again and this is a copy&paste mistake.
Why are people so hung up about this examples web application? It always
has been best practice to remove it and the other web applications in
production environments and to only deploy your own web app.
Sebastian
---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]