maven package report

Is org.apache.tomcat:tomcat-jasper safe?

3 known vulnerabilities, worst severity CRITICAL.

cvss
9.0

how bad it is if exploited, out of 10

epss
10.3%

chance of exploitation in the next 30 days

xyz score
4.3

CyberXYZ composite, out of 10

fig. 01 — GHSA-4v3g-g84w-hv7r, the advisory selected below

// advisories

GHSA-4v3g-g84w-hv7r

CRITICALCVE-2016-5018

In Apache Tomcat 9.0.0.M1 to 9.0.0.M9, 8.5.0 to 8.5.4, 8.0.0.RC1 to 8.0.36, 7.0.0 to 7.0.70 and 6.0.0 to 6.0.45 a malicious web application was able to bypass a configured SecurityManager via a Tomcat utility method that was accessible to web applications.

Affected
>= 8.5.0, <= 8.5.4, >= 7.0.0, <= 7.0.70, >= 9.0.0.M1, <= 9.0.0.M9, >= 8.0.0RC1, <= 8.0.36
Fixed in
8.5.5
Weakness
CWE-288
Published
2022-05-13
Source
github

GHSANVDMITREreferencereferencereferencereferencereferencereferencereferencereferencereference


// ai model usage

Tracked for PyPI packages. HuggingFace models declare Python dependencies, so maven packages are not covered.


Checked 2026-09-22 at 02:38 UTC. The most recent advisory here was published 2024-11-18. Updated continuously from NVD, GHSA, OSV and CNA feeds.

Think a verdict here is wrong? Tell us — we respond within 2 business days.
Is org.apache.tomcat:tomcat-jasper safe? maven package security report | CyberXYZ