Re: Tomcat 10.1 Http11NioProtocol with the OpenSSLImplementation does not sent close_notify in response to client's close_notify

2024-08-30 Thread Mark Thomas
On 29/08/2024 14:05, Christopher Schultz wrote: Isaac, On 8/26/24 13:24, Isaac Klickstein wrote: What is the "Tomcat Native Client"? I am using the Tomcat Native software (maybe "client" was wrong) available here to build the OpenSSLImplementation: https://tomcat.apache.org/download-native.

Re: Tomcat takes over 1 minute to stop

2024-08-30 Thread Quoc Nguyen
Thank you Mr. Shultz !!! We've had warnings like the below forever. I can confirm that these have not affected stopping in anyway whatsoever. WARNING [Catalina-utility-11] org.apache.catalina.loader.WebappClassLoaderBase.clearReferencesThreads The web application [web app name] appears to have

Re: Apache Tomcat Upgrade to address Curl and libcurl vulnerabilities

2024-08-30 Thread Thomas Meyer
Am 30. August 2024 16:20:24 MESZ schrieb Mark Thomas : >On 30/08/2024 15:15, Kenan, John wrote: >> Apache Tomcat Security Team: Hi, >> Please advise when an update to Apache Tomcat will be released that >> addresses the following Curl and libcurl security vulnerabilities: > >What makes you t

Re: Apache Tomcat Upgrade to address Curl and libcurl vulnerabilities

2024-08-30 Thread Mark Thomas
On 30/08/2024 15:15, Kenan, John wrote: Apache Tomcat Security Team: Please advise when an update to Apache Tomcat will be released that addresses the following Curl and libcurl security vulnerabilities: What makes you think Tomcat has a dependency on Curl and/or libcurl? Mark Critical:

Re: Apache Tomcat Upgrade to address Curl and libcurl vulnerabilities

2024-08-30 Thread Christopher Schultz
John, On 8/30/24 10:15, Kenan, John wrote: Please advise when an update to Apache Tomcat will be released that addresses the following Curl and libcurl security vulnerabilities: Critical: CVE-2023-38545 High: CVE-2024-7264 Medium: CVE-2023-46218 CVE-2023-46219 CVE-2024-0853 Low: CVE-2023-385

Apache Tomcat Upgrade to address Curl and libcurl vulnerabilities

2024-08-30 Thread Kenan, John
Apache Tomcat Security Team: Please advise when an update to Apache Tomcat will be released that addresses the following Curl and libcurl security vulnerabilities: Critical: CVE-2023-38545 High: CVE-2024-7264 Medium: CVE-2023-46218 CVE-2023-46219 CVE-2024-0853 Low: CVE-2023-38546 Thank you,

RE: Understanding ResorceLink property inheritance

2024-08-30 Thread Marcelo de Sena Lacerda
That solved the problem. I thought that I had ran into a problem where tomcat couldn't find the classorg.apache.naming.factory.DataSourceLinkFactory before but it must have been something else. De: Mark Thomas Enviado: quinta-feira, 29 de agosto de 2024 13:48 Para