Re: Further improvements to the CVE-2024-56337 protection

2025-02-21 Thread Mark Thomas
On 20/02/2025 15:23, Mark Thomas wrote: I'm making progress with the updates for Tomcat 11. Should have something to commit soon. That took longer than expected but I think that work is complete. In most cases users shouldn't see anything. If Tomcat does encounter a scenario it can't fix,

Re: Further improvements to the CVE-2024-56337 protection

2025-02-20 Thread Mark Thomas
On 20/02/2025 13:52, Rémy Maucherat wrote: On Thu, Feb 20, 2025 at 2:42 PM Mark Thomas wrote: On 20/02/2025 13:36, Rémy Maucherat wrote: On Thu, Feb 20, 2025 at 1:06 PM Mark Thomas wrote: All, The recent releases have improved things for users of embedded Tomcat but there are still some i

Re: Further improvements to the CVE-2024-56337 protection

2025-02-20 Thread Rémy Maucherat
On Thu, Feb 20, 2025 at 2:42 PM Mark Thomas wrote: > > On 20/02/2025 13:36, Rémy Maucherat wrote: > > On Thu, Feb 20, 2025 at 1:06 PM Mark Thomas wrote: > >> > >> All, > >> > >> The recent releases have improved things for users of embedded Tomcat > >> but there are still some issues. I am seeing

Re: Further improvements to the CVE-2024-56337 protection

2025-02-20 Thread Mark Thomas
On 20/02/2025 13:36, Rémy Maucherat wrote: On Thu, Feb 20, 2025 at 1:06 PM Mark Thomas wrote: All, The recent releases have improved things for users of embedded Tomcat but there are still some issues. I am seeing reports via $work related to Spring Boot. The problem is on Windows and Mac. T

Re: Further improvements to the CVE-2024-56337 protection

2025-02-20 Thread Rémy Maucherat
On Thu, Feb 20, 2025 at 1:06 PM Mark Thomas wrote: > > All, > > The recent releases have improved things for users of embedded Tomcat > but there are still some issues. I am seeing reports via $work related > to Spring Boot. > > The problem is on Windows and Mac. The file systems are case insensit

Further improvements to the CVE-2024-56337 protection

2025-02-20 Thread Mark Thomas
All, The recent releases have improved things for users of embedded Tomcat but there are still some issues. I am seeing reports via $work related to Spring Boot. The problem is on Windows and Mac. The file systems are case insensitive and DirResourceSet instances are read/write by default so