svn commit: r1887027 - in /tomcat/site/trunk: docs/security-10.html docs/security-7.html docs/security-8.html docs/security-9.html xdocs/security-10.xml xdocs/security-7.xml xdocs/security-8.xml xdocs

2021-03-01 Thread markt
Author: markt Date: Mon Mar 1 11:03:55 2021 New Revision: 1887027 URL: http://svn.apache.org/viewvc?rev=1887027&view=rev Log: Add details for CVE-2021-25122 and CVE-2021-25329 Modified: tomcat/site/trunk/docs/security-10.html tomcat/site/trunk/docs/security-7.html tomcat/site/trunk/d

[SECURITY] CVE-2021-25122 Apache Tomcat h2c request mix-up

2021-03-01 Thread Mark Thomas
CVE-2021-25122 h2c request mix-up Severity: Important Vendor: The Apache Software Foundation Versions Affected: Apache Tomcat 10.0.0-M1 to 10.0.0 Apache Tomcat 9.0.0.M1 to 9.0.41 Apache Tomcat 8.5.0 to 8.5.61 Description: When responding to new h2c connection requests, Apache Tomcat could dup

[SECURITY] CVE-2021-25329 Apache Tomcat Incomplete fix for CVE-2020-9484 (RCE via session persistence)

2021-03-01 Thread Mark Thomas
CVE-2021-25329 Incomplete fix for CVE-2020-9484 (RCE via session persistence) Severity: Low Vendor: The Apache Software Foundation Versions Affected: Apache Tomcat 10.0.0-M1 to 10.0.0 Apache Tomcat 9.0.0.M1 to 9.0.41 Apache Tomcat 8.5.0 to 8.5.61 Apache Tomcat 7.0.0 to 7.0.107 Description: T

[Bug 64762] CoyoteInputStream getInputStream() read (wait after premature end and the rest comes)

2021-03-01 Thread bugzilla
https://bz.apache.org/bugzilla/show_bug.cgi?id=64762 Matafagafo changed: What|Removed |Added CC||matafag...@yahoo.com -- You are receivin

[tomcat] branch 9.0.x updated (f0c1c8f -> ae9117e)

2021-03-01 Thread markt
This is an automated email from the ASF dual-hosted git repository. markt pushed a change to branch 9.0.x in repository https://gitbox.apache.org/repos/asf/tomcat.git. from f0c1c8f Improvements to Chinese translations. Provided by shawn. add ae9117e Fix BZ 64938 Clarify expected behav

[tomcat] branch master updated: Fix formatting

2021-03-01 Thread markt
This is an automated email from the ASF dual-hosted git repository. markt pushed a commit to branch master in repository https://gitbox.apache.org/repos/asf/tomcat.git The following commit(s) were added to refs/heads/master by this push: new 8fffdf2 Fix formatting 8fffdf2 is described belo

[tomcat] branch 9.0.x updated (ae9117e -> a72e130)

2021-03-01 Thread markt
This is an automated email from the ASF dual-hosted git repository. markt pushed a change to branch 9.0.x in repository https://gitbox.apache.org/repos/asf/tomcat.git. from ae9117e Fix BZ 64938 Clarify expected behaviour of setCharacterEncoding(null) add a72e130 Fix formatting No ne

[tomcat] branch 8.5.x updated: Align more closely with 9.0.x to simplify back-ports

2021-03-01 Thread markt
This is an automated email from the ASF dual-hosted git repository. markt pushed a commit to branch 8.5.x in repository https://gitbox.apache.org/repos/asf/tomcat.git The following commit(s) were added to refs/heads/8.5.x by this push: new 0320f99 Align more closely with 9.0.x to simplify

[Bug 64938] response.setCharacterEncoding(null) should clear previous charset

2021-03-01 Thread bugzilla
https://bz.apache.org/bugzilla/show_bug.cgi?id=64938 Mark Thomas changed: What|Removed |Added Status|NEW |RESOLVED Resolution|---

[tomcat] branch master updated: Update to BND 5.3.0

2021-03-01 Thread markt
This is an automated email from the ASF dual-hosted git repository. markt pushed a commit to branch master in repository https://gitbox.apache.org/repos/asf/tomcat.git The following commit(s) were added to refs/heads/master by this push: new 0d6a544 Update to BND 5.3.0 0d6a544 is described

[tomcat] branch 9.0.x updated: Update to BND 5.3.0

2021-03-01 Thread markt
This is an automated email from the ASF dual-hosted git repository. markt pushed a commit to branch 9.0.x in repository https://gitbox.apache.org/repos/asf/tomcat.git The following commit(s) were added to refs/heads/9.0.x by this push: new dd9ef1f Update to BND 5.3.0 dd9ef1f is described b

[tomcat] branch 8.5.x updated: Fix BZ 64938 Clarify expected behaviour of setCharacterEncoding(null)

2021-03-01 Thread markt
This is an automated email from the ASF dual-hosted git repository. markt pushed a commit to branch 8.5.x in repository https://gitbox.apache.org/repos/asf/tomcat.git The following commit(s) were added to refs/heads/8.5.x by this push: new 12ac01b Fix BZ 64938 Clarify expected behaviour of