Am 24.08.23 um 01:31 schrieb Mark Thomas:
The proposed Apache Tomcat 8.5.93 release is now available for voting.
The notable changes compared to 8.5.92 are:
- If an application or library sets both a non-500 error code and the
jakarta.servlet.error.exception</code> request attribute, use the
provided error code during error page processing rather than assuming
an error code of 500.
- Fix for FORM authentication open redirect - CVE-2023-41080
Along with lots of other bug fixes and improvements.
For full details, see the changelog:
https://nightlies.apache.org/tomcat/tomcat-8.5.x/docs/changelog.html
It can be obtained from:
https://dist.apache.org/repos/dist/dev/tomcat/tomcat-8/v8.5.93/
The Maven staging repo is:
https://repository.apache.org/content/repositories/orgapachetomcat-1454
The tag is:
https://github.com/apache/tomcat/tree/8.5.93/
9d9aea65c435a38c737c1e600e6513f9d0980cf1
The proposed 8.5.93 release is:
[ ] Broken - do not release
[ ] Stable - go ahead and release as 8.5.93 (stable)
Tests ongoing, but just a short note: The changelog still has the
previous version .92 above the newest section instead of .93. For me
this is not a show stopper and we can fix the online one after the
release. The tags for TC 9, 10.1 and 11 do not have this problem.
Best regards,
Rainer
---------------------------------------------------------------------
To unsubscribe, e-mail: dev-unsubscr...@tomcat.apache.org
For additional commands, e-mail: dev-h...@tomcat.apache.org