Re: Question regarding CVE-2018-11784

2018-10-29 Thread Christopher Schultz
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Yoli, On 10/29/18 08:18, Mark Thomas wrote: > On 29/10/18 11:29, Yoli Mana wrote: >> Hi All, >> >> Looking at the description of the below vulnerability. It is not >> clear to me if this is only relevant to those who use Tomcat for >> serving stati

Re: Question regarding CVE-2018-11784

2018-10-29 Thread Mark Thomas
On 29/10/18 11:29, Yoli Mana wrote: > Hi All, > > Looking at the description of the below vulnerability. It is not clear to > me if this is only relevant to those who use Tomcat for serving static > files (since they are talking about directory redirection). > If our Tomcat instance is used only t

Question regarding CVE-2018-11784

2018-10-29 Thread Yoli Mana
Hi All, Looking at the description of the below vulnerability. It is not clear to me if this is only relevant to those who use Tomcat for serving static files (since they are talking about directory redirection). If our Tomcat instance is used only to serve dynamic content, is the vulnerability is