Re: AW: Regarding apache-tomcat 10.1.58 version
Mark Thomas <[email protected]>
| Newsgroups | gmane.comp.jakarta.tomcat.user |
|---|---|
| Message-ID | <[email protected]> |
On 05/08/2026 11:34, Roshan Patil wrote: > Dear Team, > > There is no |*examples*|directory in the Apache Tomcat |webapps| > directory. I need only 10.1.58 to resolve VA. Please assist. If there is no examples directory (which I assume means the examples web application is not deployed), why do you need 10.1.58? Mark > > Regards, > Roshan Patil, > > On 8/5/2026 12:52 PM, Döscher, Andreas (ESI) via users wrote: >> Moin, >> examples and documentation should always be removed in productive >> environments, therefore >> >>> 4. If the vulnerability only affects the *examples*web application >>> (specifically the WebSocket chat example), would removing the >>> *examples*web application be considered sufficient mitigation until >>> the fixed version becomes available? >> is the way! >> >> Ciao, >> Andreas >> >> PS: With documentation an attacker could be able to determine the >> version of the tomcat. Please consult the security-howto.html of the >> tomcat documentation. >> >> -----Ursprüngliche Nachricht----- >> Von: Roshan Patil<[email protected]> >> Gesendet: Mittwoch, 5. August 2026 09:10 >> An:[email protected];[email protected] >> Cc: Ahmad Hassan<[email protected]> >> Betreff: Regarding apache-tomcat 10.1.58 version >> >> >> ********************************************************************** >> Dear Team, >> >> I hope you are doing well. >> >> We are currently performing security remediation based on a >> Vulnerability Assessment (VA) report. >> >> The report indicates that our Apache Tomcat installation is >> affected by *CVE-2026-66299*and recommends upgrading to *Apache Tomcat >> 10.1.58 or later*. The advisory states that the issue affects Apache >> Tomcat versions *10.1.24 through 10.1.57*and is fixed in *10.1.58*. >> >> However, we are unable to find Apache Tomcat *10.1.58*on the >> official Apache Tomcat download page or archives. >> >> The relevant portion of the VA report is as follows: >> >> o *CVE:*CVE-2026-66299 >> o *Affected versions:*Apache Tomcat 10.1.24 through 10.1.57 >> o *Recommended remediation:*Upgrade to Apache Tomcat 10.1.58 or >> later. >> o *Additional note:*Nessus relies on the application's >> self-reported version number. >> >> Could you please help us with the following: >> >> 1. Has Apache Tomcat *10.1.58*been officially released? >> 2. If not, when is it expected to be available? >> 3. Is there an alternative fixed version that we should upgrade to in >> order to remediate CVE-2026-66299? >> 4. If the vulnerability only affects the *examples*web application >> (specifically the WebSocket chat example), would removing the >> *examples*web application be considered sufficient mitigation until >> the fixed version becomes available? >> >> We appreciate your guidance, as we need to complete our organization's >> security remediation and close the VA findings. >> >> Regards, >> >> Roshan Patil >> ------------------------------------------------------------------------------------------------------------ >> [ C-DAC is on Social-Media too. Kindly follow us at: >> Facebook:https://urldefense.com/v3/__https://www.facebook.com/ >> CDACINDIA__;!!L8-7AA!U0klxdOOErOsRMyOyk- >> cIdGn01ljqxmXVvyJmh4FurKHf_kDx- >> qBpw6y4q85AE302jkPDXM4N2QePq4DdOm1S7OW$ & Twitter: @cdacindia ] >> >> This e-mail is for the sole use of the intended recipient(s) and may >> contain confidential and privileged information. If you are not the >> intended recipient, please contact the sender by reply e-mail and >> destroy all copies and the original message. Any unauthorized review, >> use, disclosure, dissemination, forwarding, printing or copying of >> this email is strictly prohibited and appropriate legal action will be >> taken. >> ------------------------------------------------------------------------------------------------------------ >> >> >> >> This message and any attachments are intended only for the use of the >> addressee and may contain information that is privileged and >> confidential. If the reader of the message is not the intended >> recipient or an authorized representative of the intended recipient, >> you are hereby notified that any dissemination of this communication >> is strictly prohibited. If you have received this communication in >> error, notify the sender immediately by return email and delete the >> message and any attachments from your system. >> >> --------------------------------------------------------------------- >> To unsubscribe, e-mail:[email protected] >> For additional commands, e-mail:[email protected] >> > ------------------------------------------------------------------------------------------------------------ > [ C-DAC is on Social-Media too. Kindly follow us at: > Facebook: https://www.facebook.com/CDACINDIA & Twitter: @cdacindia ] > > This e-mail is for the sole use of the intended recipient(s) and may > contain confidential and privileged information. If you are not the > intended recipient, please contact the sender by reply e-mail and destroy > all copies and the original message. Any unauthorized review, use, > disclosure, dissemination, forwarding, printing or copying of this email > is strictly prohibited and appropriate legal action will be taken. > ------------------------------------------------------------------------------------------------------------ > >