[Bug 69608] JSP Servlet engine is garbage collected leading to Denial of service

2025-03-12 Thread bugzilla
https://bz.apache.org/bugzilla/show_bug.cgi?id=69608 --- Comment #6 from Chen Jp --- Could try CATALINA_OPTS="-Xms10g -Xmx10g"? -- You are receiving this mail because: You are the assignee for the bug. - To unsubscribe, e-mail:

(tomcat) branch 9.0.x updated: Cleanup, no functional change

2025-03-12 Thread remm
This is an automated email from the ASF dual-hosted git repository. remm pushed a commit to branch 9.0.x in repository https://gitbox.apache.org/repos/asf/tomcat.git The following commit(s) were added to refs/heads/9.0.x by this push: new 33c8ef24c6 Cleanup, no functional change 33c8ef24c6

(tomcat) branch 11.0.x updated: Cleanup, no functional change

2025-03-12 Thread remm
This is an automated email from the ASF dual-hosted git repository. remm pushed a commit to branch 11.0.x in repository https://gitbox.apache.org/repos/asf/tomcat.git The following commit(s) were added to refs/heads/11.0.x by this push: new 894d529375 Cleanup, no functional change 894d52937

(tomcat) branch 10.1.x updated: Cleanup, no functional change

2025-03-12 Thread remm
This is an automated email from the ASF dual-hosted git repository. remm pushed a commit to branch 10.1.x in repository https://gitbox.apache.org/repos/asf/tomcat.git The following commit(s) were added to refs/heads/10.1.x by this push: new b31fe06bda Cleanup, no functional change b31fe06bd

(tomcat) branch main updated: Cleanup, no functional change

2025-03-12 Thread remm
This is an automated email from the ASF dual-hosted git repository. remm pushed a commit to branch main in repository https://gitbox.apache.org/repos/asf/tomcat.git The following commit(s) were added to refs/heads/main by this push: new 5c3bfd95c6 Cleanup, no functional change 5c3bfd95c6 is

svn commit: r1924346 - /tomcat/site/trunk/docs/tomcat-11.0-doc/changelog.html

2025-03-12 Thread schultz
Author: schultz Date: Wed Mar 12 22:07:45 2025 New Revision: 1924346 URL: http://svn.apache.org/viewvc?rev=1924346&view=rev Log: Correct CVE identifier Modified: tomcat/site/trunk/docs/tomcat-11.0-doc/changelog.html Modified: tomcat/site/trunk/docs/tomcat-11.0-doc/changelog.html URL: http:/

[Bug 69612] Typo on the release notes of Catalina 11.0.3 ('CVE-2004-56337' instead of 'CVE-2024-56337')

2025-03-12 Thread bugzilla
https://bz.apache.org/bugzilla/show_bug.cgi?id=69612 Christopher Schultz changed: What|Removed |Added Status|NEW |RESOLVED Resolution|---

(tomcat) branch 11.0.x updated: Correct CVE identifier

2025-03-12 Thread schultz
This is an automated email from the ASF dual-hosted git repository. schultz pushed a commit to branch 11.0.x in repository https://gitbox.apache.org/repos/asf/tomcat.git The following commit(s) were added to refs/heads/11.0.x by this push: new 101eb5f320 Correct CVE identifier 101eb5f320 is

[Bug 69612] New: Typo on the release notes of Catalina 11.0.3 ('CVE-2004-56337' instead of 'CVE-2024-56337')

2025-03-12 Thread bugzilla
https://bz.apache.org/bugzilla/show_bug.cgi?id=69612 Bug ID: 69612 Summary: Typo on the release notes of Catalina 11.0.3 ('CVE-2004-56337' instead of 'CVE-2024-56337') Product: Tomcat 11 Version: 11.0.3 Hardware: All

Re: [PR] Added support for JDBC 4.3 beginRequest and endRequest methods. [tomcat]

2025-03-12 Thread via GitHub
fmeheust commented on PR #677: URL: https://github.com/apache/tomcat/pull/677#issuecomment-2718315476 Hi @aooohan and @ahai-code this contribution has been approved for a while, is it possible to have an idea on when it will be comitted? Thank you! -- This is an automated message from th

(tomcat) branch main updated (837ecbc08f -> 6233d129a2)

2025-03-12 Thread remm
This is an automated email from the ASF dual-hosted git repository. remm pushed a change to branch main in repository https://gitbox.apache.org/repos/asf/tomcat.git from 837ecbc08f Cleanups add 6233d129a2 Use new language features No new revisions were added by this update. Summary of

Re: Default Servlet and POST

2025-03-12 Thread Rémy Maucherat
On Wed, Mar 12, 2025 at 1:23 PM Mark Thomas wrote: > > All, > > I have been working through the some specification compliance questions > raised by some research into HTTP conformance [1]. > > That paper's focus is security but I don't see any security concerns for > Tomcat. I do see a number of f

Default Servlet and POST

2025-03-12 Thread Mark Thomas
All, I have been working through the some specification compliance questions raised by some research into HTTP conformance [1]. That paper's focus is security but I don't see any security concerns for Tomcat. I do see a number of false positive results and I have raised issues for those. O

(tomcat) branch 9.0.x updated: Cleanups

2025-03-12 Thread remm
This is an automated email from the ASF dual-hosted git repository. remm pushed a commit to branch 9.0.x in repository https://gitbox.apache.org/repos/asf/tomcat.git The following commit(s) were added to refs/heads/9.0.x by this push: new 2cde1c9078 Cleanups 2cde1c9078 is described below c

(tomcat) branch 10.1.x updated: Cleanups

2025-03-12 Thread remm
This is an automated email from the ASF dual-hosted git repository. remm pushed a commit to branch 10.1.x in repository https://gitbox.apache.org/repos/asf/tomcat.git The following commit(s) were added to refs/heads/10.1.x by this push: new 64c21e8971 Cleanups 64c21e8971 is described below

(tomcat) branch 11.0.x updated: Cleanups

2025-03-12 Thread remm
This is an automated email from the ASF dual-hosted git repository. remm pushed a commit to branch 11.0.x in repository https://gitbox.apache.org/repos/asf/tomcat.git The following commit(s) were added to refs/heads/11.0.x by this push: new 130c3a033b Cleanups 130c3a033b is described below

(tomcat) branch main updated: Cleanups

2025-03-12 Thread remm
This is an automated email from the ASF dual-hosted git repository. remm pushed a commit to branch main in repository https://gitbox.apache.org/repos/asf/tomcat.git The following commit(s) were added to refs/heads/main by this push: new 837ecbc08f Cleanups 837ecbc08f is described below com

[Bug 69610] New: Consider implementing support for upgrade-insecure-requests request header and conditional HSTS

2025-03-12 Thread bugzilla
https://bz.apache.org/bugzilla/show_bug.cgi?id=69610 Bug ID: 69610 Summary: Consider implementing support for upgrade-insecure-requests request header and conditional HSTS Product: Tomcat 11 Version: unspecified