Re: [tomcat] branch master updated: Happy New Year 2021

2021-01-19 Thread Christopher Schultz
Mark, It seems like this could be easier if we defined a string constant or two somewhere and referenced it from everywhere. For the JSP files, perhaps the Manager web application could stuff the copyright notice into the servlet (application) context on startup and the JSP could pull the va

Re: [tomcat] branch master updated: Happy New Year 2021

2021-01-19 Thread Mark Thomas
On 19/01/2021 17:26, Christopher Schultz wrote: > Mark, > > It seems like this could be easier if we defined a string constant or > two somewhere and referenced it from everywhere. Another of life's constants appears to be that there is an XKCD for every situation: https://xkcd.com/1205/ Given

Re: [SECURITY][CORRECTION] CVE-2020-17527 Apache Tomcat HTTP/2 Request header mix-up

2021-01-19 Thread Mark Thomas
Please note the updated affected version information below. Mark On 03/12/2020 18:01, Mark Thomas wrote: > CVE-2020-17527 Apache Tomcat HTTP/2 Request header mix-up > > Severity: Moderate > > Vendor: The Apache Software Foundation > > Versions Affected: > Apache Tomcat 10.0.0-M1 to 10.0.0-M9

svn commit: r1885694 - in /tomcat/site/trunk: docs/security-8.html xdocs/security-8.xml

2021-01-19 Thread markt
Author: markt Date: Tue Jan 19 18:11:59 2021 New Revision: 1885694 URL: http://svn.apache.org/viewvc?rev=1885694&view=rev Log: Fix typo Modified: tomcat/site/trunk/docs/security-8.html tomcat/site/trunk/xdocs/security-8.xml Modified: tomcat/site/trunk/docs/security-8.html URL: http://sv