Re: Apache Tomcat Upgrade to address Curl and libcurl vulnerabilities

2024-08-30 Thread Thomas Meyer
Am 30. August 2024 16:20:24 MESZ schrieb Mark Thomas : >On 30/08/2024 15:15, Kenan, John wrote: >> Apache Tomcat Security Team: Hi, >> Please advise when an update to Apache Tomcat will be released that >> addresses the following Curl and libcurl security vulnerabilities: > >What makes you t

Re: Apache Tomcat Upgrade to address Curl and libcurl vulnerabilities

2024-08-30 Thread Mark Thomas
On 30/08/2024 15:15, Kenan, John wrote: Apache Tomcat Security Team: Please advise when an update to Apache Tomcat will be released that addresses the following Curl and libcurl security vulnerabilities: What makes you think Tomcat has a dependency on Curl and/or libcurl? Mark Critical:

Re: Apache Tomcat Upgrade to address Curl and libcurl vulnerabilities

2024-08-30 Thread Christopher Schultz
John, On 8/30/24 10:15, Kenan, John wrote: Please advise when an update to Apache Tomcat will be released that addresses the following Curl and libcurl security vulnerabilities: Critical: CVE-2023-38545 High: CVE-2024-7264 Medium: CVE-2023-46218 CVE-2023-46219 CVE-2024-0853 Low: CVE-2023-385

Apache Tomcat Upgrade to address Curl and libcurl vulnerabilities

2024-08-30 Thread Kenan, John
Apache Tomcat Security Team: Please advise when an update to Apache Tomcat will be released that addresses the following Curl and libcurl security vulnerabilities: Critical: CVE-2023-38545 High: CVE-2024-7264 Medium: CVE-2023-46218 CVE-2023-46219 CVE-2024-0853 Low: CVE-2023-38546 Thank you,