[Bug 61542] Apache Tomcat Remote Code Execution via JSP Upload bypass

2024-06-27 Thread bugzilla
https://bz.apache.org/bugzilla/show_bug.cgi?id=61542 Chuck Caldarale changed: What|Removed |Added URL|https://forum.czaswojny.int | |eria.pl/index.ph

[Bug 61542] Apache Tomcat Remote Code Execution via JSP Upload bypass

2024-06-27 Thread bugzilla
https://bz.apache.org/bugzilla/show_bug.cgi?id=61542 jhon005 changed: What|Removed |Added URL|https://animex2.statuspage. |https://forum.czaswojny.int

[Bug 57665] support x-forwarded-host

2024-06-27 Thread bugzilla
https://bz.apache.org/bugzilla/show_bug.cgi?id=57665 jhon005 changed: What|Removed |Added URL||https://animex2.statuspage.

[Bug 61542] Apache Tomcat Remote Code Execution via JSP Upload bypass

2024-06-27 Thread bugzilla
https://bz.apache.org/bugzilla/show_bug.cgi?id=61542 jhon005 changed: What|Removed |Added URL||https://animex2.statuspage.

[Bug 57665] support x-forwarded-host

2024-06-27 Thread bugzilla
https://bz.apache.org/bugzilla/show_bug.cgi?id=57665 --- Comment #25 from jhon005 --- https://www.merdeka.com/?c=%3Ch1%3E%3Ca%20href=%22https://gogoanimex.me/category/nierautomata-ver1-1a%22%3Enierautomata-ver1-1a-gogoanime%3C/a%3E%3C/h1%3E https://www.flexmls.com/cgi-bin/mainmenu.cgi?cmd=url+sea

[Bug 61542] Apache Tomcat Remote Code Execution via JSP Upload bypass

2024-06-27 Thread bugzilla
https://bz.apache.org/bugzilla/show_bug.cgi?id=61542 --- Comment #12 from jhon005 --- https://www.atoallinks.com/2022/how-does-gogoanime-stand-apart-from-different-sites/ https://www.addonface.com/read-blog/8286_gogoanime-features-and-things-to-be-aware-of-gogoanime.html https://www.onfeetnation

(tomcat) branch main updated: Revert following failed testing

2024-06-27 Thread remm
This is an automated email from the ASF dual-hosted git repository. remm pushed a commit to branch main in repository https://gitbox.apache.org/repos/asf/tomcat.git The following commit(s) were added to refs/heads/main by this push: new f57681c6ef Revert following failed testing f57681c6ef

(tomcat) branch main updated: Retest new library loading code on MacOS using GH CI

2024-06-27 Thread remm
This is an automated email from the ASF dual-hosted git repository. remm pushed a commit to branch main in repository https://gitbox.apache.org/repos/asf/tomcat.git The following commit(s) were added to refs/heads/main by this push: new e4ffa0fe09 Retest new library loading code on MacOS us

(tomcat) branch main updated: Revert

2024-06-27 Thread remm
This is an automated email from the ASF dual-hosted git repository. remm pushed a commit to branch main in repository https://gitbox.apache.org/repos/asf/tomcat.git The following commit(s) were added to refs/heads/main by this push: new 26d30fc0b7 Revert 26d30fc0b7 is described below commi

Buildbot success in on tomcat-11.0.x

2024-06-27 Thread buildbot
Build status: Build succeeded! Worker used: bb_worker2_ubuntu URL: https://ci2.apache.org/#builders/112/builds/1157 Blamelist: Mark Thomas , remm Build Text: build successful Status Detected: restored build Build Source Stamp: [branch main] 62567d8321ef8fae2f4c07d0b617281b3952ce2b Steps: work

(tomcat) branch main updated: Remove continue-on-error

2024-06-27 Thread remm
This is an automated email from the ASF dual-hosted git repository. remm pushed a commit to branch main in repository https://gitbox.apache.org/repos/asf/tomcat.git The following commit(s) were added to refs/heads/main by this push: new cde8ceabf8 Remove continue-on-error cde8ceabf8 is desc

(tomcat) branch 10.1.x updated: Try to adjust for Windows

2024-06-27 Thread remm
This is an automated email from the ASF dual-hosted git repository. remm pushed a commit to branch 10.1.x in repository https://gitbox.apache.org/repos/asf/tomcat.git The following commit(s) were added to refs/heads/10.1.x by this push: new 7d90dd6bc5 Try to adjust for Windows 7d90dd6bc5 is

Buildbot success in on tomcat-9.0.x

2024-06-27 Thread buildbot
Build status: Build succeeded! Worker used: bb_worker2_ubuntu URL: https://ci2.apache.org/#builders/37/builds/993 Blamelist: Mark Thomas , remm Build Text: build successful Status Detected: restored build Build Source Stamp: [branch 9.0.x] 4f63ee0786ce9d2a1af5df7e1f054bff06a7 Steps: worke

(tomcat) branch main updated: Try to adjust for Windows

2024-06-27 Thread remm
This is an automated email from the ASF dual-hosted git repository. remm pushed a commit to branch main in repository https://gitbox.apache.org/repos/asf/tomcat.git The following commit(s) were added to refs/heads/main by this push: new 62567d8321 Try to adjust for Windows 62567d8321 is des

[Bug 61542] Apache Tomcat Remote Code Execution via JSP Upload bypass

2024-06-27 Thread bugzilla
https://bz.apache.org/bugzilla/show_bug.cgi?id=61542 Chuck Caldarale changed: What|Removed |Added URL|https://forum.czaswojny.int | |eria.pl/index.ph

[Bug 61542] Apache Tomcat Remote Code Execution via JSP Upload bypass

2024-06-27 Thread bugzilla
https://bz.apache.org/bugzilla/show_bug.cgi?id=61542 user1000 <2305g...@navalcadets.com> changed: What|Removed |Added URL||https://forum.czas

Re: Reduce default for maxParameterCount

2024-06-27 Thread Christopher Schultz
Michael, On 6/27/24 08:46, Michael Osipov wrote: On 2023/03/09 14:23:33 Christopher Schultz wrote: A potential use-case for "large numbers of parameters" might be an application that uses something like a multi-select list and the number of choices is stupendously high. As in, when the applicat

Buildbot failure in on tomcat-11.0.x

2024-06-27 Thread buildbot
Build status: BUILD FAILED: failed compile (failure) Worker used: bb_worker2_ubuntu URL: https://ci2.apache.org/#builders/112/builds/1156 Blamelist: Mark Thomas Build Text: failed compile (failure) Status Detected: new failure Build Source Stamp: [branch main] 2d47ecf17f23593fd18c3285467531ff5e154

Re: (tomcat) branch main updated: Remove cglib dependency

2024-06-27 Thread Christopher Schultz
Mark, \O/ | -chris On 6/26/24 11:45, ma...@apache.org wrote: This is an automated email from the ASF dual-hosted git repository. markt pushed a commit to branch main in repository https://gitbox.apache.org/repos/asf/tomcat.git The following commit(s) were added to refs/heads/main by this p

Re: [tomcat] 02/03: Experimenting with Semgrep

2024-06-27 Thread Christopher Schultz
All, On 6/26/24 11:38, Mark Thomas wrote: On 26/06/2024 16:30, Rémy Maucherat wrote: On Wed, Sep 13, 2023 at 12:53 PM Mark Thomas wrote: On 13/09/2023 11:18, ma...@apache.org wrote: This is an automated email from the ASF dual-hosted git repository. markt pushed a commit to branch main in

[Bug 61877] use web.xml from CATALINA_HOME by default

2024-06-27 Thread bugzilla
https://bz.apache.org/bugzilla/show_bug.cgi?id=61877 --- Comment #10 from Christopher Schultz --- :( -- You are receiving this mail because: You are the assignee for the bug. - To unsubscribe, e-mail: dev-unsubscr...@tomcat.apa

[Bug 69016] HttpURLConnection getOutputStream createCapacityException

2024-06-27 Thread bugzilla
https://bz.apache.org/bugzilla/show_bug.cgi?id=69016 --- Comment #8 from Christopher Schultz --- We probably need an "InvalidArgumentException" with a nice error message as well as a documentation-fix. That error message is not readable by "normal people" :) -- You are receiving this mail beca

Re: Clarifications and Suggestions on Tomcat Native Binary Distributions

2024-06-27 Thread Christopher Schultz
Mark, On 6/24/24 08:14, Mark Thomas wrote: On 21/06/2024 15:35, Dimitris Soumis wrote: Hi all, I hope this message finds you well. I am writing to seek clarifications and provide some suggestions regarding the Tomcat Native binary distributions. Firstly, I have noticed that openssl.exe is i

(tomcat) branch 9.0.x updated: Fix Java 11 source compatibility

2024-06-27 Thread markt
This is an automated email from the ASF dual-hosted git repository. markt pushed a commit to branch 9.0.x in repository https://gitbox.apache.org/repos/asf/tomcat.git The following commit(s) were added to refs/heads/9.0.x by this push: new 4f63ee Fix Java 11 source compatibility 4f6

(tomcat) 04/04: Fix Java 11 source compatibility

2024-06-27 Thread markt
This is an automated email from the ASF dual-hosted git repository. markt pushed a commit to branch 10.1.x in repository https://gitbox.apache.org/repos/asf/tomcat.git commit fb7adcd900242da3e7c5f13deeeb3d79b22a2327 Author: Mark Thomas AuthorDate: Thu Jun 27 17:34:09 2024 +0100 Fix Java 11

(tomcat) 02/04: Expand BZ 69135 fix - fix relative includes inside JAR file

2024-06-27 Thread markt
This is an automated email from the ASF dual-hosted git repository. markt pushed a commit to branch 10.1.x in repository https://gitbox.apache.org/repos/asf/tomcat.git commit 06b311e3ee7504c9a565399c252a362e939e7607 Author: Mark Thomas AuthorDate: Thu Jun 27 14:52:59 2024 +0100 Expand BZ 69

(tomcat) 01/04: Partial fix for BZ 69135

2024-06-27 Thread markt
This is an automated email from the ASF dual-hosted git repository. markt pushed a commit to branch 10.1.x in repository https://gitbox.apache.org/repos/asf/tomcat.git commit c6b35f33ea4eda5b4b524b4e4b74abfe00920d47 Author: Mark Thomas AuthorDate: Thu Jun 27 12:30:47 2024 +0100 Partial fix

(tomcat) 03/04: Complete fixes for BZ 69135 - prevent escape from /META-INF/tags/

2024-06-27 Thread markt
This is an automated email from the ASF dual-hosted git repository. markt pushed a commit to branch 10.1.x in repository https://gitbox.apache.org/repos/asf/tomcat.git commit f23b1ac92a8ae474e9c810201d6a579a90264cf6 Author: Mark Thomas AuthorDate: Thu Jun 27 17:25:49 2024 +0100 Complete fix

(tomcat) branch 10.1.x updated (92c37fb1fb -> fb7adcd900)

2024-06-27 Thread markt
This is an automated email from the ASF dual-hosted git repository. markt pushed a change to branch 10.1.x in repository https://gitbox.apache.org/repos/asf/tomcat.git from 92c37fb1fb Fix NIO only check new c6b35f33ea Partial fix for BZ 69135 new 06b311e3ee Expand BZ 69135 fix - fi

(tomcat) 02/03: Expand BZ 69135 fix - fix relative includes inside JAR file

2024-06-27 Thread markt
This is an automated email from the ASF dual-hosted git repository. markt pushed a commit to branch main in repository https://gitbox.apache.org/repos/asf/tomcat.git commit be232ad503db678c7326d8faba7466f6c36b11df Author: Mark Thomas AuthorDate: Thu Jun 27 14:52:59 2024 +0100 Expand BZ 6913

(tomcat) branch main updated (2ef17f020f -> 2d47ecf17f)

2024-06-27 Thread markt
This is an automated email from the ASF dual-hosted git repository. markt pushed a change to branch main in repository https://gitbox.apache.org/repos/asf/tomcat.git from 2ef17f020f Fix NIO only check new 658b5b61e9 Partial fix for BZ 69135 new be232ad503 Expand BZ 69135 fix - fix

(tomcat) 01/03: Partial fix for BZ 69135

2024-06-27 Thread markt
This is an automated email from the ASF dual-hosted git repository. markt pushed a commit to branch main in repository https://gitbox.apache.org/repos/asf/tomcat.git commit 658b5b61e90673bb9c526efeee874213f7e70872 Author: Mark Thomas AuthorDate: Thu Jun 27 12:30:47 2024 +0100 Partial fix fo

(tomcat) 03/03: Complete fixes for BZ 69135 - prevent escape from /META-INF/tags/

2024-06-27 Thread markt
This is an automated email from the ASF dual-hosted git repository. markt pushed a commit to branch main in repository https://gitbox.apache.org/repos/asf/tomcat.git commit 2d47ecf17f23593fd18c3285467531ff5e1545e8 Author: Mark Thomas AuthorDate: Thu Jun 27 17:25:49 2024 +0100 Complete fixes

Buildbot success in on tomcat-11.0.x

2024-06-27 Thread buildbot
Build status: Build succeeded! Worker used: bb_worker2_ubuntu URL: https://ci2.apache.org/#builders/112/builds/1155 Blamelist: remm Build Text: build successful Status Detected: restored build Build Source Stamp: [branch main] 2ef17f020fcffaf0383e9789f481ff4aae9df8e3 Steps: worker_preparation

Buildbot failure in on tomcat-9.0.x

2024-06-27 Thread buildbot
Build status: BUILD FAILED: failed compile (failure) Logs copied. (failure) Worker used: bb_worker2_ubuntu URL: https://ci2.apache.org/#builders/37/builds/991 Blamelist: remm Build Text: failed compile (failure) Logs copied. (failure) Status Detected: new failure Build Source Stamp: [branch 9.0.x]

(tomcat) branch 9.0.x updated: Fix NIO only check

2024-06-27 Thread remm
This is an automated email from the ASF dual-hosted git repository. remm pushed a commit to branch 9.0.x in repository https://gitbox.apache.org/repos/asf/tomcat.git The following commit(s) were added to refs/heads/9.0.x by this push: new 3c1ff43668 Fix NIO only check 3c1ff43668 is describe

(tomcat) branch 10.1.x updated: Fix NIO only check

2024-06-27 Thread remm
This is an automated email from the ASF dual-hosted git repository. remm pushed a commit to branch 10.1.x in repository https://gitbox.apache.org/repos/asf/tomcat.git The following commit(s) were added to refs/heads/10.1.x by this push: new 92c37fb1fb Fix NIO only check 92c37fb1fb is descri

(tomcat) branch main updated: Fix NIO only check

2024-06-27 Thread remm
This is an automated email from the ASF dual-hosted git repository. remm pushed a commit to branch main in repository https://gitbox.apache.org/repos/asf/tomcat.git The following commit(s) were added to refs/heads/main by this push: new 2ef17f020f Fix NIO only check 2ef17f020f is described

Buildbot failure in on tomcat-10.1.x

2024-06-27 Thread buildbot
Build status: BUILD FAILED: failed compile (failure) Logs copied. (failure) Worker used: bb_worker2_ubuntu URL: https://ci2.apache.org/#builders/44/builds/1307 Blamelist: remm Build Text: failed compile (failure) Logs copied. (failure) Status Detected: new failure Build Source Stamp: [branch 10.1.

Buildbot failure in on tomcat-11.0.x

2024-06-27 Thread buildbot
Build status: BUILD FAILED: failed compile (failure) Worker used: bb_worker2_ubuntu URL: https://ci2.apache.org/#builders/112/builds/1154 Blamelist: remm Build Text: failed compile (failure) Status Detected: new failure Build Source Stamp: [branch main] de7b89c3c9935c7db421d5deea2a1410a2968c27 S

(tomcat-tck) 02/02: Remove unused imports

2024-06-27 Thread markt
This is an automated email from the ASF dual-hosted git repository. markt pushed a commit to branch main in repository https://gitbox.apache.org/repos/asf/tomcat-tck.git commit 8f3a678a8457eccc685c1aaa1ba06ef150cdfac6 Author: Mark Thomas AuthorDate: Thu Jun 27 12:15:45 2024 +0100 Remove unu

(tomcat-tck) 01/02: Bump version under test to 11.0.0-M21

2024-06-27 Thread markt
This is an automated email from the ASF dual-hosted git repository. markt pushed a commit to branch main in repository https://gitbox.apache.org/repos/asf/tomcat-tck.git commit 0920cf4b41d3b2862ecc4435c077d15cd6205873 Author: Mark Thomas AuthorDate: Mon Jun 24 15:32:39 2024 +0100 Bump versi

(tomcat-tck) branch main updated (d89e488 -> 8f3a678)

2024-06-27 Thread markt
This is an automated email from the ASF dual-hosted git repository. markt pushed a change to branch main in repository https://gitbox.apache.org/repos/asf/tomcat-tck.git from d89e488 No longer required new 0920cf4 Bump version under test to 11.0.0-M21 new 8f3a678 Remove unused i

(tomcat) branch 9.0.x updated: Fix detailed view of a connector with auto port

2024-06-27 Thread remm
This is an automated email from the ASF dual-hosted git repository. remm pushed a commit to branch 9.0.x in repository https://gitbox.apache.org/repos/asf/tomcat.git The following commit(s) were added to refs/heads/9.0.x by this push: new 772c39df53 Fix detailed view of a connector with aut

(tomcat) branch 10.1.x updated: Fix detailed view of a connector with auto port

2024-06-27 Thread remm
This is an automated email from the ASF dual-hosted git repository. remm pushed a commit to branch 10.1.x in repository https://gitbox.apache.org/repos/asf/tomcat.git The following commit(s) were added to refs/heads/10.1.x by this push: new 79469a8d86 Fix detailed view of a connector with a

(tomcat) branch main updated: Fix detailed view of a connector with auto port

2024-06-27 Thread remm
This is an automated email from the ASF dual-hosted git repository. remm pushed a commit to branch main in repository https://gitbox.apache.org/repos/asf/tomcat.git The following commit(s) were added to refs/heads/main by this push: new de7b89c3c9 Fix detailed view of a connector with auto

(tomcat) branch main updated: Performance tests are already excluded

2024-06-27 Thread remm
This is an automated email from the ASF dual-hosted git repository. remm pushed a commit to branch main in repository https://gitbox.apache.org/repos/asf/tomcat.git The following commit(s) were added to refs/heads/main by this push: new b3646ed4c1 Performance tests are already excluded b364

(tomcat) branch 10.1.x updated: Only tomcat-native needs the extra initializeSSL call

2024-06-27 Thread remm
This is an automated email from the ASF dual-hosted git repository. remm pushed a commit to branch 10.1.x in repository https://gitbox.apache.org/repos/asf/tomcat.git The following commit(s) were added to refs/heads/10.1.x by this push: new 9091500a81 Only tomcat-native needs the extra init

(tomcat) branch main updated: Only tomcat-native needs the extra initializeSSL call

2024-06-27 Thread remm
This is an automated email from the ASF dual-hosted git repository. remm pushed a commit to branch main in repository https://gitbox.apache.org/repos/asf/tomcat.git The following commit(s) were added to refs/heads/main by this push: new a810be5a10 Only tomcat-native needs the extra initiali