Re: Question regarding CVE-2018-11784

2018-10-29 Thread Christopher Schultz
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Yoli, On 10/29/18 08:18, Mark Thomas wrote: > On 29/10/18 11:29, Yoli Mana wrote: >> Hi All, >> >> Looking at the description of the below vulnerability. It is not >> clear to me if this is only relevant to those who use Tomcat for >> serving stati

Re: Question regarding CVE-2018-11784

2018-10-29 Thread Mark Thomas
On 29/10/18 11:29, Yoli Mana wrote: > Hi All, > > Looking at the description of the below vulnerability. It is not clear to > me if this is only relevant to those who use Tomcat for serving static > files (since they are talking about directory redirection). > If our Tomcat instance is used only t