Re: Looking for useless information. :-)

2021-03-05 Thread Gavin McDonald
Hi, On Fri, Mar 5, 2021 at 10:40 PM wrote: > Hi All. > > I have a team hounding me for the release date of Tomcat 3.1 and I'm not > able to find it so far. Anyone remember this ancient history? > Back then, as part of the Jakarta project, I believe it was 19th April 2000 See:- http://mail-arc

Looking for useless information. :-)

2021-03-05 Thread jonmcalexander
Hi All. I have a team hounding me for the release date of Tomcat 3.1 and I'm not able to find it so far. Anyone remember this ancient history? Thanks, Dream * Excel * Explore * Inspire Jon McAlexander Infrastructure Engineer Asst Vice President Middleware Product Engineering Enterprise CIO |

Re: [SECURITY] CVE-2021-25122 Apache Tomcat h2c request mix-up

2021-03-05 Thread r00t 4dm
Cherish the word as gold. Regards, r00t4dm Cloud-Penetrating Arrow Lab of Meituan Corp Information Security Department > 2021年3月5日 下午5:48,Mark Thomas 写道: > > On 05/03/2021 08:20, Kursu, Teemu wrote: >> Hi, >> Just to make sure that I understand this correctly. Does this vulnerability >> affect

Re: [SECURITY] CVE-2021-25122 Apache Tomcat h2c request mix-up

2021-03-05 Thread Mark Thomas
On 05/03/2021 08:20, Kursu, Teemu wrote: Hi, Just to make sure that I understand this correctly. Does this vulnerability affect in both http1.1 and http2 protocols? No. I mean is this vulnerability still relevant if HTTP Upgrade Protocol is not implemented in server.xml? No. Mark Reg

RE: [SECURITY] CVE-2021-25122 Apache Tomcat h2c request mix-up

2021-03-05 Thread Kursu, Teemu
Hi, Just to make sure that I understand this correctly. Does this vulnerability affect in both http1.1 and http2 protocols? I mean is this vulnerability still relevant if HTTP Upgrade Protocol is not implemented in server.xml? Regards, Teemu Kursu -Original Message- From: Mark Thomas