The Apache Tomcat Team have announced the immediate availability of Tomcat version 7.0.42.
This new release fixes several issues including one security issue related to Javadoc vulnerabilities. The highlights include:
As usual, full details of changes in this release can be found in the project's changelog.
This new version of Tomcat can be downloaded from the project's download site.
This new release fixes several issues including one security issue related to Javadoc vulnerabilities. The highlights include:
- Add support for time to first byte in the AccessLogValve. Patch provided by Jeremy Boynes.
- Correct a regression introduced in 7.0.39 (refactoring of base 64 encoding and decoding) that broke the JNDI Realm when userPassword was set and passwords were hashed with MD5 or SHA1.
- Ensure that the build process produces Javadoc that is not vulnerable to CVE-2013-1571. Based on a patch by Uwe Schindler.
As usual, full details of changes in this release can be found in the project's changelog.
This new version of Tomcat can be downloaded from the project's download site.
Comments
Post a Comment