Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Upgraded to Tomcat Oktober security release #669

Merged
merged 1 commit into from
Oct 16, 2023

Conversation

StefanPenndorf
Copy link
Contributor

Fixes several Tomcat CVE:

Upgrade includes

  • Tomcat 8.5.94 from 8.5 line
  • Tomcat 9.0.81 from 9.0 line
  • Tomcat 10.1.14 from 10.1 line (will be new default version)
  • Tomcat 11.0.0-M12 as latest from 11 line (this is the latest alpha release)

Tomcat 11.0.0-M10 dropped because it's only an alpha release and superseded by M10.

Fixes several Tomcat CVE:
- Important: Request smuggling CVE-2023-45648
- Important: Denial of Service CVE-2023-44487
- Important: Information Disclosure CVE-2023-42795
- Low: Denial of Service CVE-2023-42794

Upgrade includes
- Tomcat 8.5.94 from 8.5 line
- Tomcat 9.0.81 from 9.0 line
- Tomcat 10.1.14 from 10.1 line (will be new default version)
- Tomcat 11.0.0-M12 as latest from 11 line (this is the latest alpha release)

Tomcat 11.0.0-M10 dropped because it's only an alpha release and superseded by M10.
@marc0der
Copy link
Member

LGTM, thanks for your contribution!

@marc0der marc0der merged commit e09421e into sdkman:master Oct 16, 2023
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants