[Bug 61542] Apache Tomcat Remote Code Execution via JSP Upload bypass

2018-06-14 Thread bugzilla
https://bz.apache.org/bugzilla/show_bug.cgi?id=61542 --- Comment #12 from Castro B --- Hello Mark, does this issue fixed already? Or any source? Thanks Castro B. http://buywebtrafficexperts.com/"; -- You are receiving this mail because: You are the assignee for the bug. ---

[Bug 62455] CORS filter cors.allowed.origins does not default to "*" anymore

2018-06-14 Thread bugzilla
https://bz.apache.org/bugzilla/show_bug.cgi?id=62455 --- Comment #1 from Konstantin Kolinko --- Looking at your version number (8.0.32), it is likely that you are using not the official version of Tomcat from tomcat.apache.org, but a repackaged version from a Linux vendor. As the security issue

[Bug 62455] New: CORS filter cors.allowed.origins does not default to "*" anymore

2018-06-14 Thread bugzilla
https://bz.apache.org/bugzilla/show_bug.cgi?id=62455 Bug ID: 62455 Summary: CORS filter cors.allowed.origins does not default to "*" anymore Product: Tomcat 8 Version: 8.0.32 Hardware: Other OS: other