Tomcat Authentication + Spring Security J2EEPreAuthentication

2019-05-17 Thread Nacho Ganguli
HELP, I NEED SOMEBODY, NOT JUST ANYBODY! HELP (It all started weeks ago when I tried unsuccessfully to use Tomcat's SSO Valve and decided to try pre-authentication...) We are developing a subscription-based "portal" webapp that we use to authenticate users and perform authentication flows su

[SECURITY] CVE-2019-0221 Apache Tomcat XSS in SSI printenv

2019-05-17 Thread Mark Thomas
CVE-2019-0221 Apache Tomcat XSS in SSI printenv Severity: Low Vendor: The Apache Software Foundation Versions Affected: Apache Tomcat 9.0.0.M1 to 9.0.17 Apache Tomcat 8.5.0 to 8.5.39 Apache Tomcat 7.0.0 to 7.0.93 Description: The SSI printenv command echoes user provided data without escaping a