+1: fhanik,funkman
-1:
-* Fix important vulnerability when webdav is enabled for write
- Patch: http://marc.info/?l=tomcat-dev&m=119245116910632&w=2
- +1: markt, funkman, remm, fhanik
- -1:
-
* Fix for JDT update: update jdt.jar in build.properties.default to:
jdt.jar=${jdt.lib}/org.eclipse.jdt.core_3.3.1.v_780_R33x.jar
+1: remm, fhanik,funkman, pero
try {
documentBuilderFactory = DocumentBuilderFactory.newInstance();
documentBuilderFactory.setNamespaceAware(true);
+ documentBuilderFactory.setExpandEntityReferences(false);
documentBuilder = documentBuilderFactory.newDocumentBuilder();
} catch(ParserConfigurationException e) {
throw new ServletException
Fix WebDAV Servlet so it works correctly with MS clients. (markt)
</fix>
<fix>
+ Fix CVE-2007-5461, an important information disclosure vulnerability in
+ the WebDAV Servlet. (markt)
+ </fix>
+ <fix>
<bug>42979</bug>: Update sample.war to include recent security fixes
in the source code. (markt)
</fix>