Bug report for Tomcat Connectors [2021/02/07]

2021-02-06 Thread bugzilla
+---+ | Bugzilla Bug ID | | +-+ | | Status: UNC=Unconfirmed NEW=New ASS=Assigned

Bug report for Tomcat Modules [2021/02/07]

2021-02-06 Thread bugzilla
+---+ | Bugzilla Bug ID | | +-+ | | Status: UNC=Unconfirmed NEW=New ASS=Assigned

Bug report for Tomcat 8 [2021/02/07]

2021-02-06 Thread bugzilla
+---+ | Bugzilla Bug ID | | +-+ | | Status: UNC=Unconfirmed NEW=New ASS=Assigned

Bug report for Tomcat 9 [2021/02/07]

2021-02-06 Thread bugzilla
+---+ | Bugzilla Bug ID | | +-+ | | Status: UNC=Unconfirmed NEW=New ASS=Assigned

Bug report for Tomcat Native [2021/02/07]

2021-02-06 Thread bugzilla
+---+ | Bugzilla Bug ID | | +-+ | | Status: UNC=Unconfirmed NEW=New ASS=Assigned

Bug report for Tomcat 7 [2021/02/07]

2021-02-06 Thread bugzilla
+---+ | Bugzilla Bug ID | | +-+ | | Status: UNC=Unconfirmed NEW=New ASS=Assigned

Bug report for Taglibs [2021/02/07]

2021-02-06 Thread bugzilla
+---+ | Bugzilla Bug ID | | +-+ | | Status: UNC=Unconfirmed NEW=New ASS=Assigned

[Bug 65126] New: A security vulnerability cve-2020-1971 in Tomcat dependency Library in version 9.0.40.

2021-02-06 Thread bugzilla
https://bz.apache.org/bugzilla/show_bug.cgi?id=65126 Bug ID: 65126 Summary: A security vulnerability cve-2020-1971 in Tomcat dependency Library in version 9.0.40. Product: Tomcat 9 Version: 9.0.39 Hardware: PC S

[jira] [Commented] (MTOMCAT-323) Avoid using plaintext Keystore password in source code

2021-02-06 Thread Mark Thomas (Jira)
[ https://issues.apache.org/jira/browse/MTOMCAT-323?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17280273#comment-17280273 ] Mark Thomas commented on MTOMCAT-323: - In my astonishment I forgot to mention that p

[jira] [Comment Edited] (MTOMCAT-323) Avoid using plaintext Keystore password in source code

2021-02-06 Thread Mark Thomas (Jira)
[ https://issues.apache.org/jira/browse/MTOMCAT-323?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17280270#comment-17280270 ] Mark Thomas edited comment on MTOMCAT-323 at 2/6/21, 7:50 PM:

[jira] [Resolved] (MTOMCAT-323) Avoid using plaintext Keystore password in source code

2021-02-06 Thread Mark Thomas (Jira)
[ https://issues.apache.org/jira/browse/MTOMCAT-323?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Mark Thomas resolved MTOMCAT-323. - Resolution: Invalid I am frankly astonished that anyone involved in security research would thin

[jira] [Updated] (MTOMCAT-323) Avoid using plaintext Keystore password in source code

2021-02-06 Thread Ying Zhang (Jira)
[ https://issues.apache.org/jira/browse/MTOMCAT-323?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Ying Zhang updated MTOMCAT-323: --- Description: We are a security research team at Virginia Tech. We are doing an empirical study abou

[jira] [Created] (MTOMCAT-323) Avoid using plaintext Keystore password in source code

2021-02-06 Thread Ying Zhang (Jira)
Ying Zhang created MTOMCAT-323: -- Summary: Avoid using plaintext Keystore password in source code Key: MTOMCAT-323 URL: https://issues.apache.org/jira/browse/MTOMCAT-323 Project: Apache Tomcat Maven Plug