Re: [PR] Bump org.apache.tomcat:tomcat-catalina from 11.0.0-M22 to 11.0.0 in /modules/stuffed [tomcat]

2024-11-18 Thread via GitHub
dependabot[bot] closed pull request #781: Bump org.apache.tomcat:tomcat-catalina from 11.0.0-M22 to 11.0.0 in /modules/stuffed URL: https://github.com/apache/tomcat/pull/781 -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use

(tomcat) branch dependabot/maven/modules/stuffed/org.apache.tomcat-tomcat-catalina-11.0.0 deleted (was 5e156a1a17)

2024-11-18 Thread github-bot
This is an automated email from the ASF dual-hosted git repository. github-bot pushed a change to branch dependabot/maven/modules/stuffed/org.apache.tomcat-tomcat-catalina-11.0.0 in repository https://gitbox.apache.org/repos/asf/tomcat.git was 5e156a1a17 Bump org.apache.tomcat:tomcat-catal

Re: [PR] Bump org.apache.tomcat:tomcat-catalina from 11.0.0-M22 to 11.0.0 in /modules/stuffed [tomcat]

2024-11-18 Thread via GitHub
dependabot[bot] commented on PR #781: URL: https://github.com/apache/tomcat/pull/781#issuecomment-2484937892 Looks like org.apache.tomcat:tomcat-catalina is up-to-date now, so this is no longer needed. -- This is an automated message from the Apache Git Service. To respond to the message,

(tomcat) branch main updated: Use snapshot version (mute dependabot)

2024-11-18 Thread remm
This is an automated email from the ASF dual-hosted git repository. remm pushed a commit to branch main in repository https://gitbox.apache.org/repos/asf/tomcat.git The following commit(s) were added to refs/heads/main by this push: new e036e99802 Use snapshot version (mute dependabot) e036

[PR] send 416 error to overlapping ranges request [tomcat]

2024-11-18 Thread via GitHub
Chenjp opened a new pull request, #782: URL: https://github.com/apache/tomcat/pull/782 request ranges validation - overlap detection added. * invalid ranges - overlapping: ``` D:\git\github.com>curl http://localhost:55464/index.html -i -H "Range: bytes=10-40,35-50" HTTP/1.1 4

(tomcat) branch dependabot/maven/modules/stuffed/org.apache.tomcat-tomcat-catalina-11.0.0 created (now 5e156a1a17)

2024-11-18 Thread github-bot
This is an automated email from the ASF dual-hosted git repository. github-bot pushed a change to branch dependabot/maven/modules/stuffed/org.apache.tomcat-tomcat-catalina-11.0.0 in repository https://gitbox.apache.org/repos/asf/tomcat.git at 5e156a1a17 Bump org.apache.tomcat:tomcat-catal

[PR] Bump org.apache.tomcat:tomcat-catalina from 11.0.0-M22 to 11.0.0 in /modules/stuffed [tomcat]

2024-11-18 Thread via GitHub
dependabot[bot] opened a new pull request, #781: URL: https://github.com/apache/tomcat/pull/781 Bumps org.apache.tomcat:tomcat-catalina from 11.0.0-M22 to 11.0.0. [![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=

Re: (tomcat) branch main updated: Avoid quotes for numbers in JSON from status servlet

2024-11-18 Thread Christopher Schultz
Rémy, On 11/18/24 2:52 PM, r...@apache.org wrote: This is an automated email from the ASF dual-hosted git repository. remm pushed a commit to branch main in repository https://gitbox.apache.org/repos/asf/tomcat.git The following commit(s) were added to refs/heads/main by this push: new

(tomcat) branch 10.1.x updated: Avoid quotes for numbers in JSON from status servlet

2024-11-18 Thread remm
This is an automated email from the ASF dual-hosted git repository. remm pushed a commit to branch 10.1.x in repository https://gitbox.apache.org/repos/asf/tomcat.git The following commit(s) were added to refs/heads/10.1.x by this push: new a6546c4207 Avoid quotes for numbers in JSON from s

(tomcat) branch 9.0.x updated: Avoid quotes for numbers in JSON from status servlet

2024-11-18 Thread remm
This is an automated email from the ASF dual-hosted git repository. remm pushed a commit to branch 9.0.x in repository https://gitbox.apache.org/repos/asf/tomcat.git The following commit(s) were added to refs/heads/9.0.x by this push: new fbf3afa907 Avoid quotes for numbers in JSON from sta

(tomcat) branch 11.0.x updated: Avoid quotes for numbers in JSON from status servlet

2024-11-18 Thread remm
This is an automated email from the ASF dual-hosted git repository. remm pushed a commit to branch 11.0.x in repository https://gitbox.apache.org/repos/asf/tomcat.git The following commit(s) were added to refs/heads/11.0.x by this push: new 550129d9b7 Avoid quotes for numbers in JSON from s

(tomcat) branch main updated: Avoid quotes for numbers in JSON from status servlet

2024-11-18 Thread remm
This is an automated email from the ASF dual-hosted git repository. remm pushed a commit to branch main in repository https://gitbox.apache.org/repos/asf/tomcat.git The following commit(s) were added to refs/heads/main by this push: new 445363c4fe Avoid quotes for numbers in JSON from statu

(tomcat) branch 11.0.x updated: Fix BZ 69444 - set jakarta.servlet.error.message for error pages

2024-11-18 Thread markt
This is an automated email from the ASF dual-hosted git repository. markt pushed a commit to branch 11.0.x in repository https://gitbox.apache.org/repos/asf/tomcat.git The following commit(s) were added to refs/heads/11.0.x by this push: new b9a2c8ad37 Fix BZ 69444 - set jakarta.servlet.err

[Bug 69444] jakarta.servlet.error.message request attribute should be empty string instead of null

2024-11-18 Thread bugzilla
https://bz.apache.org/bugzilla/show_bug.cgi?id=69444 Mark Thomas changed: What|Removed |Added Resolution|--- |FIXED Status|NEW

(tomcat) branch 9.0.x updated: Fix BZ 69444 - set javax.servlet.error.message for error pages

2024-11-18 Thread markt
This is an automated email from the ASF dual-hosted git repository. markt pushed a commit to branch 9.0.x in repository https://gitbox.apache.org/repos/asf/tomcat.git The following commit(s) were added to refs/heads/9.0.x by this push: new c302462764 Fix BZ 69444 - set javax.servlet.error.m

(tomcat) branch 10.1.x updated: Fix BZ 69444 - set jakarta.servlet.error.message for error pages

2024-11-18 Thread markt
This is an automated email from the ASF dual-hosted git repository. markt pushed a commit to branch 10.1.x in repository https://gitbox.apache.org/repos/asf/tomcat.git The following commit(s) were added to refs/heads/10.1.x by this push: new eca49efd30 Fix BZ 69444 - set jakarta.servlet.err

(tomcat) branch main updated: Fix BZ 69444 - set jakarta.servlet.error.message for error pages

2024-11-18 Thread markt
This is an automated email from the ASF dual-hosted git repository. markt pushed a commit to branch main in repository https://gitbox.apache.org/repos/asf/tomcat.git The following commit(s) were added to refs/heads/main by this push: new 6d87f07765 Fix BZ 69444 - set jakarta.servlet.error.m

[Bug 69446] HttpServlet doPut - storage exhausted without maxFileSize limitation

2024-11-18 Thread bugzilla
https://bz.apache.org/bugzilla/show_bug.cgi?id=69446 Mark Thomas changed: What|Removed |Added Status|NEW |RESOLVED Resolution|---

Re: [PR] fix multipart/byteranges response body - length attri of ContentRange [tomcat]

2024-11-18 Thread via GitHub
rmaucher commented on PR #780: URL: https://github.com/apache/tomcat/pull/780#issuecomment-2483051390 Merged in main, 11 and 10.1. Test case added to 9.0. -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above t

Re: [PR] fix multipart/byteranges response body - length attri of ContentRange [tomcat]

2024-11-18 Thread via GitHub
rmaucher closed pull request #780: fix multipart/byteranges response body - length attri of ContentRange URL: https://github.com/apache/tomcat/pull/780 -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go t

(tomcat) branch 9.0.x updated: Add test case for content-range

2024-11-18 Thread remm
This is an automated email from the ASF dual-hosted git repository. remm pushed a commit to branch 9.0.x in repository https://gitbox.apache.org/repos/asf/tomcat.git The following commit(s) were added to refs/heads/9.0.x by this push: new 0229838ec4 Add test case for content-range 0229838ec

(tomcat) branch 10.1.x updated: Fix content-range header length

2024-11-18 Thread remm
This is an automated email from the ASF dual-hosted git repository. remm pushed a commit to branch 10.1.x in repository https://gitbox.apache.org/repos/asf/tomcat.git The following commit(s) were added to refs/heads/10.1.x by this push: new 7d8ff3108f Fix content-range header length 7d8ff31

(tomcat) branch 11.0.x updated: Fix content-range header length

2024-11-18 Thread remm
This is an automated email from the ASF dual-hosted git repository. remm pushed a commit to branch 11.0.x in repository https://gitbox.apache.org/repos/asf/tomcat.git The following commit(s) were added to refs/heads/11.0.x by this push: new b72d7da173 Fix content-range header length b72d7da

(tomcat) branch main updated: Fix content-range header length

2024-11-18 Thread remm
This is an automated email from the ASF dual-hosted git repository. remm pushed a commit to branch main in repository https://gitbox.apache.org/repos/asf/tomcat.git The following commit(s) were added to refs/heads/main by this push: new 382872c6d3 Fix content-range header length 382872c6d3

[SECURITY] CVE-2024-52318 Apache Tomcat - XSS in generated JSPs

2024-11-18 Thread Mark Thomas
CVE-2024-52318 Apache Tomcat - XSS in generated JSPs Severity: Important Vendor: The Apache Software Foundation Versions Affected: Apache Tomcat 11.0.0 Apache Tomcat 10.1.31 Apache Tomcat 9.0.96 Description: The fix for improvement 69333 [0] caused pooled JSP tags not to be released after use

svn commit: r1921933 - in /tomcat/site/trunk: docs/security-10.html docs/security-11.html docs/security-9.html xdocs/security-10.xml xdocs/security-11.xml xdocs/security-9.xml

2024-11-18 Thread markt
Author: markt Date: Mon Nov 18 12:18:01 2024 New Revision: 1921933 URL: http://svn.apache.org/viewvc?rev=1921933&view=rev Log: CVE-2024-52318 Modified: tomcat/site/trunk/docs/security-10.html tomcat/site/trunk/docs/security-11.html tomcat/site/trunk/docs/security-9.html tomcat/sit

[SECURITY] CVE-2024-52317 Apache Tomcat - Request and/or response mix-up

2024-11-18 Thread Mark Thomas
Note: Correction to 10.1.x affected versions CVE-2024-52317 Apache Tomcat - Request and/or response mix-up Severity: Important Vendor: The Apache Software Foundation Versions Affected: Apache Tomcat 11.0.0-M23 to 11.0.0-M26 Apache Tomcat 10.1.27 to 10.1.30 Apache Tomcat 9.0.92 to 9.0.95 Descr

[SECURITY] CVE-2024-52317 Apache Tomcat - Request and/or response mix-up

2024-11-18 Thread Mark Thomas
CVE-2024-52317 Apache Tomcat - Request and/or response mix-up Severity: Important Vendor: The Apache Software Foundation Versions Affected: Apache Tomcat 11.0.0-M23 to 11.0.0-M26 Apache Tomcat 10.1.7 to 10.1.30 Apache Tomcat 9.0.92 to 9.0.95 Description: Incorrect recycling of the request and

[SECURITY] CVE-2024-52316 Apache Tomcat - Authentication Bypass

2024-11-18 Thread Mark Thomas
CVE-2024-52316 Apache Tomcat - Authentication Bypass Severity: Low Vendor: The Apache Software Foundation Versions Affected: Apache Tomcat 11.0.0-M1 to 11.0.0-M26 Apache Tomcat 10.1.0-M1 to 10.1.30 Apache Tomcat 9.0.0-M1 to 9.0.95 Description: If Tomcat was configured to use a custom Jakarta A

svn commit: r1921932 - in /tomcat/site/trunk: docs/security-10.html docs/security-11.html docs/security-9.html xdocs/security-10.xml xdocs/security-11.xml xdocs/security-9.xml

2024-11-18 Thread markt
Author: markt Date: Mon Nov 18 11:17:42 2024 New Revision: 1921932 URL: http://svn.apache.org/viewvc?rev=1921932&view=rev Log: CVE-2024-52316 and CVE-2024-52317 Modified: tomcat/site/trunk/docs/security-10.html tomcat/site/trunk/docs/security-11.html tomcat/site/trunk/docs/security-9.

[Bug 69456] New: We are launching A Fortune teller. That will tells your Fortune in Just one click. If you want to check your Fortune please Visit on our website: Crystal Ball Online

2024-11-18 Thread bugzilla
https://bz.apache.org/bugzilla/show_bug.cgi?id=69456 Bug ID: 69456 Summary: We are launching A Fortune teller. That will tells your Fortune in Just one click. If you want to check your Fortune please Visit on our website: Crystal Ball

[Bug 69455] New: We are launching A Fortune teller. That will tells your Fortune in Just one click. If you want to check your Fortune please Visit on our website: Vintage Magic 8 Ball Online

2024-11-18 Thread bugzilla
https://bz.apache.org/bugzilla/show_bug.cgi?id=69455 Bug ID: 69455 Summary: We are launching A Fortune teller. That will tells your Fortune in Just one click. If you want to check your Fortune please Visit on our website: Vintage

[Bug 69458] New: We have launched a Button to help you in making your Decision Better and Soon. If you want to check your answer in Yes/No please Visit on our Official Website: Bluey Yes No Button

2024-11-18 Thread bugzilla
https://bz.apache.org/bugzilla/show_bug.cgi?id=69458 Bug ID: 69458 Summary: We have launched a Button to help you in making your Decision Better and Soon. If you want to check your answer in Yes/No please Visit on our Official Website:

[Bug 69451] New: We are launching A Fortune teller. That will tells your Fortune in Just one click. If you want to check your Fortune please Visit on our website: Magic 8 Ball Oracle Online

2024-11-18 Thread bugzilla
https://bz.apache.org/bugzilla/show_bug.cgi?id=69451 Bug ID: 69451 Summary: We are launching A Fortune teller. That will tells your Fortune in Just one click. If you want to check your Fortune please Visit on our website: Magic 8 Ball