[SECURITY] Apache Tomcat and CVE-2021-44228 (Log4j vulnerability)

2021-12-14 Thread Mark Thomas
The following represents the current understanding of the Apache Tomcat security team at the time this announcement was issued. There is a lot of security research being focussed on log4j2 at the moment and it is probable that additional information will emerge. Currently supported Tomcat vers

Tomcat 8.5.74

2021-12-14 Thread Christopher Schultz
All, Apologies for not matching the release-cadence of Tomcat 10.x and 9.x this month. I will try to begin the process later today. If anyone wants to get anything in before the release, please let me know and I'll hold off a little. Thanks for your patience. -chris ---

Re: [tomcat] branch 10.0.x updated: Add change log entry for BZ 65724

2021-12-14 Thread Rainer Jung
Minor typo in changelog, probably all branches noted below. Am 06.12.2021 um 09:40 schrieb ma...@apache.org: This is an automated email from the ASF dual-hosted git repository. markt pushed a commit to branch 10.0.x in repository https://gitbox.apache.org/repos/asf/tomcat.git The following