Author: markt
Date: Mon Jan 31 11:14:09 2022
New Revision: 1897623

URL: http://svn.apache.org/viewvc?rev=1897623&view=rev
Log:
Improvements to the security pages. Move the ToC to after the intro so the 
intro is always visible. Make EOL statements bold so they stand out. Post 
CVE-2021-44228 we are getting a lot of questions about out of date Tomcat 
versions so make the security status of these versions clearer.

Modified:
    tomcat/site/trunk/docs/security-10.html
    tomcat/site/trunk/docs/security-3.html
    tomcat/site/trunk/docs/security-4.html
    tomcat/site/trunk/docs/security-5.html
    tomcat/site/trunk/docs/security-6.html
    tomcat/site/trunk/docs/security-7.html
    tomcat/site/trunk/docs/security-8.html
    tomcat/site/trunk/docs/security-9.html
    tomcat/site/trunk/xdocs/security-10.xml
    tomcat/site/trunk/xdocs/security-3.xml
    tomcat/site/trunk/xdocs/security-4.xml
    tomcat/site/trunk/xdocs/security-5.xml
    tomcat/site/trunk/xdocs/security-6.xml
    tomcat/site/trunk/xdocs/security-7.xml
    tomcat/site/trunk/xdocs/security-8.xml
    tomcat/site/trunk/xdocs/security-9.xml

Modified: tomcat/site/trunk/docs/security-10.html
URL: 
http://svn.apache.org/viewvc/tomcat/site/trunk/docs/security-10.html?rev=1897623&r1=1897622&r2=1897623&view=diff
==============================================================================
--- tomcat/site/trunk/docs/security-10.html (original)
+++ tomcat/site/trunk/docs/security-10.html Mon Jan 31 11:14:09 2022
@@ -1,7 +1,5 @@
 <!DOCTYPE html SYSTEM "about:legacy-compat">
-<html lang="en"><head><META http-equiv="Content-Type" content="text/html; 
charset=UTF-8"><meta name="viewport" content="width=device-width, 
initial-scale=1"><link href="res/css/tomcat.css" rel="stylesheet" 
type="text/css"><link href="res/css/fonts/fonts.css" rel="stylesheet" 
type="text/css"><title>Apache Tomcat&reg; - Apache Tomcat 10 
vulnerabilities</title><meta name="author" content="Apache Tomcat 
Project"></head><body><div id="wrapper"><header id="header"><div 
class="clearfix"><div class="menu-toggler pull-left" tabindex="1"><div 
class="hamburger"></div></div><a href="http://tomcat.apache.org/";><img 
class="tomcat-logo pull-left noPrint" alt="Tomcat Home" 
src="res/images/tomcat.png"></a><h1 class="pull-left">Apache 
Tomcat<sup>&reg;</sup></h1><div class="asf-logos pull-right"><a 
href="https://www.apache.org/foundation/contributing.html"; target="_blank" 
class="pull-left"><img 
src="https://www.apache.org/images/SupportApache-small.png"; class="support-asf" 
alt="Support Apache"></a><a 
 href="http://www.apache.org/"; target="_blank" class="pull-left"><img 
src="res/images/asf_logo.svg" class="asf-logo" alt="The Apache Software 
Foundation"></a></div></div></header><main id="middle"><div><div 
id="mainLeft"><div id="nav-wrapper"><form 
action="https://www.google.com/search"; method="get"><div 
class="searchbox"><input value="tomcat.apache.org" name="sitesearch" 
type="hidden"><input aria-label="Search text" placeholder="Search&hellip;" 
required="required" name="q" id="query" 
type="search"><button>GO</button></div></form><nav><div><h2>Apache 
Tomcat</h2><ul><li><a href="./index.html">Home</a></li><li><a 
href="./taglibs.html">Taglibs</a></li><li><a href="./maven-plugin.html">Maven 
Plugin</a></li></ul></div><div><h2>Download</h2><ul><li><a 
href="./whichversion.html">Which version?</a></li><li><a 
href="https://tomcat.apache.org/download-10.cgi";>Tomcat 10</a></li><li><a 
href="https://tomcat.apache.org/download-90.cgi";>Tomcat 9</a></li><li><a 
href="https://tomcat.apache.org/downlo
 ad-80.cgi">Tomcat 8</a></li><li><a 
href="https://tomcat.apache.org/download-migration.cgi";>Tomcat Migration Tool 
for Jakarta EE</a></li><li><a 
href="https://tomcat.apache.org/download-connectors.cgi";>Tomcat 
Connectors</a></li><li><a 
href="https://tomcat.apache.org/download-native.cgi";>Tomcat 
Native</a></li><li><a 
href="https://tomcat.apache.org/download-taglibs.cgi";>Taglibs</a></li><li><a 
href="https://archive.apache.org/dist/tomcat/";>Archives</a></li></ul></div><div><h2>Documentation</h2><ul><li><a
 href="./tomcat-10.1-doc/index.html">Tomcat 10.1 (alpha)</a></li><li><a 
href="./tomcat-10.0-doc/index.html">Tomcat 10.0</a></li><li><a 
href="./tomcat-9.0-doc/index.html">Tomcat 9.0</a></li><li><a 
href="./tomcat-8.5-doc/index.html">Tomcat 8.5</a></li><li><a 
href="./connectors-doc/">Tomcat Connectors</a></li><li><a 
href="./native-doc/">Tomcat Native</a></li><li><a 
href="https://cwiki.apache.org/confluence/display/TOMCAT";>Wiki</a></li><li><a 
href="./migration.html">Migration Guide</a></li><l
 i><a href="./presentations.html">Presentations</a></li><li><a 
href="https://cwiki.apache.org/confluence/x/Bi8lBg";>Specifications</a></li></ul></div><div><h2>Problems?</h2><ul><li><a
 href="./security.html">Security Reports</a></li><li><a 
href="./findhelp.html">Find help</a></li><li><a 
href="https://cwiki.apache.org/confluence/display/TOMCAT/FAQ";>FAQ</a></li><li><a
 href="./lists.html">Mailing Lists</a></li><li><a href="./bugreport.html">Bug 
Database</a></li><li><a href="./irc.html">IRC</a></li></ul></div><div><h2>Get 
Involved</h2><ul><li><a href="./getinvolved.html">Overview</a></li><li><a 
href="./source.html">Source code</a></li><li><a 
href="./ci.html">Buildbot</a></li><li><a 
href="https://cwiki.apache.org/confluence/x/vIPzBQ";>Translations</a></li><li><a 
href="./tools.html">Tools</a></li></ul></div><div><h2>Media</h2><ul><li><a 
href="https://twitter.com/theapachetomcat";>Twitter</a></li><li><a 
href="https://www.youtube.com/c/ApacheTomcatOfficial";>YouTube</a></li><li><a 
href="https://b
 logs.apache.org/tomcat/">Blog</a></li></ul></div><div><h2>Misc</h2><ul><li><a 
href="./whoweare.html">Who We Are</a></li><li><a 
href="https://www.redbubble.com/people/comdev/works/30885254-apache-tomcat";>Swag</a></li><li><a
 href="./heritage.html">Heritage</a></li><li><a 
href="http://www.apache.org";>Apache Home</a></li><li><a 
href="./resources.html">Resources</a></li><li><a 
href="./contact.html">Contact</a></li><li><a 
href="./legal.html">Legal</a></li><li><a 
href="https://www.apache.org/foundation/contributing.html";>Support 
Apache</a></li><li><a 
href="https://www.apache.org/foundation/sponsorship.html";>Sponsorship</a></li><li><a
 href="http://www.apache.org/foundation/thanks.html";>Thanks</a></li><li><a 
href="http://www.apache.org/licenses/";>License</a></li></ul></div></nav></div></div><div
 id="mainRight"><div id="content"><h2 style="display: none;">Content</h2><h3 
id="Table_of_Contents">Table of Contents</h3><div class="text">
-<ul><li><a href="#Apache_Tomcat_10.x_vulnerabilities">Apache Tomcat 10.x 
vulnerabilities</a></li><li><a href="#Fixed_in_Apache_Tomcat_10.0.16">Fixed in 
Apache Tomcat 10.0.16</a></li><li><a 
href="#Fixed_in_Apache_Tomcat_10.1.0-M10">Fixed in Apache Tomcat 
10.1.0-M10</a></li><li><a href="#Fixed_in_Apache_Tomcat_10.0.12">Fixed in 
Apache Tomcat 10.0.12</a></li><li><a 
href="#Fixed_in_Apache_Tomcat_10.1.0-M6">Fixed in Apache Tomcat 
10.1.0-M6</a></li><li><a href="#Fixed_in_Apache_Tomcat_10.0.7">Fixed in Apache 
Tomcat 10.0.7</a></li><li><a href="#Fixed_in_Apache_Tomcat_10.0.6">Fixed in 
Apache Tomcat 10.0.6</a></li><li><a href="#Fixed_in_Apache_Tomcat_10.0.5">Fixed 
in Apache Tomcat 10.0.5</a></li><li><a 
href="#Fixed_in_Apache_Tomcat_10.0.4">Fixed in Apache Tomcat 
10.0.4</a></li><li><a href="#Fixed_in_Apache_Tomcat_10.0.2">Fixed in Apache 
Tomcat 10.0.2</a></li><li><a href="#Fixed_in_Apache_Tomcat_10.0.0-M10">Fixed in 
Apache Tomcat 10.0.0-M10</a></li><li><a href="#Fixed_in_Apache_Tomcat_10.0.0-
 M8">Fixed in Apache Tomcat 10.0.0-M8</a></li><li><a 
href="#Fixed_in_Apache_Tomcat_10.0.0-M7">Fixed in Apache Tomcat 
10.0.0-M7</a></li><li><a href="#Fixed_in_Apache_Tomcat_10.0.0-M6">Fixed in 
Apache Tomcat 10.0.0-M6</a></li><li><a 
href="#Fixed_in_Apache_Tomcat_10.0.0-M5">Fixed in Apache Tomcat 
10.0.0-M5</a></li><li><a href="#Not_a_vulnerability_in_Tomcat">Not a 
vulnerability in Tomcat</a></li></ul>
-</div><h3 id="Apache_Tomcat_10.x_vulnerabilities">Apache Tomcat 10.x 
vulnerabilities</h3><div class="text">
+<html lang="en"><head><META http-equiv="Content-Type" content="text/html; 
charset=UTF-8"><meta name="viewport" content="width=device-width, 
initial-scale=1"><link href="res/css/tomcat.css" rel="stylesheet" 
type="text/css"><link href="res/css/fonts/fonts.css" rel="stylesheet" 
type="text/css"><title>Apache Tomcat&reg; - Apache Tomcat 10 
vulnerabilities</title><meta name="author" content="Apache Tomcat 
Project"></head><body><div id="wrapper"><header id="header"><div 
class="clearfix"><div class="menu-toggler pull-left" tabindex="1"><div 
class="hamburger"></div></div><a href="http://tomcat.apache.org/";><img 
class="tomcat-logo pull-left noPrint" alt="Tomcat Home" 
src="res/images/tomcat.png"></a><h1 class="pull-left">Apache 
Tomcat<sup>&reg;</sup></h1><div class="asf-logos pull-right"><a 
href="https://www.apache.org/foundation/contributing.html"; target="_blank" 
class="pull-left"><img 
src="https://www.apache.org/images/SupportApache-small.png"; class="support-asf" 
alt="Support Apache"></a><a 
 href="http://www.apache.org/"; target="_blank" class="pull-left"><img 
src="res/images/asf_logo.svg" class="asf-logo" alt="The Apache Software 
Foundation"></a></div></div></header><main id="middle"><div><div 
id="mainLeft"><div id="nav-wrapper"><form 
action="https://www.google.com/search"; method="get"><div 
class="searchbox"><input value="tomcat.apache.org" name="sitesearch" 
type="hidden"><input aria-label="Search text" placeholder="Search&hellip;" 
required="required" name="q" id="query" 
type="search"><button>GO</button></div></form><nav><div><h2>Apache 
Tomcat</h2><ul><li><a href="./index.html">Home</a></li><li><a 
href="./taglibs.html">Taglibs</a></li><li><a href="./maven-plugin.html">Maven 
Plugin</a></li></ul></div><div><h2>Download</h2><ul><li><a 
href="./whichversion.html">Which version?</a></li><li><a 
href="https://tomcat.apache.org/download-10.cgi";>Tomcat 10</a></li><li><a 
href="https://tomcat.apache.org/download-90.cgi";>Tomcat 9</a></li><li><a 
href="https://tomcat.apache.org/downlo
 ad-80.cgi">Tomcat 8</a></li><li><a 
href="https://tomcat.apache.org/download-migration.cgi";>Tomcat Migration Tool 
for Jakarta EE</a></li><li><a 
href="https://tomcat.apache.org/download-connectors.cgi";>Tomcat 
Connectors</a></li><li><a 
href="https://tomcat.apache.org/download-native.cgi";>Tomcat 
Native</a></li><li><a 
href="https://tomcat.apache.org/download-taglibs.cgi";>Taglibs</a></li><li><a 
href="https://archive.apache.org/dist/tomcat/";>Archives</a></li></ul></div><div><h2>Documentation</h2><ul><li><a
 href="./tomcat-10.1-doc/index.html">Tomcat 10.1 (alpha)</a></li><li><a 
href="./tomcat-10.0-doc/index.html">Tomcat 10.0</a></li><li><a 
href="./tomcat-9.0-doc/index.html">Tomcat 9.0</a></li><li><a 
href="./tomcat-8.5-doc/index.html">Tomcat 8.5</a></li><li><a 
href="./connectors-doc/">Tomcat Connectors</a></li><li><a 
href="./native-doc/">Tomcat Native</a></li><li><a 
href="https://cwiki.apache.org/confluence/display/TOMCAT";>Wiki</a></li><li><a 
href="./migration.html">Migration Guide</a></li><l
 i><a href="./presentations.html">Presentations</a></li><li><a 
href="https://cwiki.apache.org/confluence/x/Bi8lBg";>Specifications</a></li></ul></div><div><h2>Problems?</h2><ul><li><a
 href="./security.html">Security Reports</a></li><li><a 
href="./findhelp.html">Find help</a></li><li><a 
href="https://cwiki.apache.org/confluence/display/TOMCAT/FAQ";>FAQ</a></li><li><a
 href="./lists.html">Mailing Lists</a></li><li><a href="./bugreport.html">Bug 
Database</a></li><li><a href="./irc.html">IRC</a></li></ul></div><div><h2>Get 
Involved</h2><ul><li><a href="./getinvolved.html">Overview</a></li><li><a 
href="./source.html">Source code</a></li><li><a 
href="./ci.html">Buildbot</a></li><li><a 
href="https://cwiki.apache.org/confluence/x/vIPzBQ";>Translations</a></li><li><a 
href="./tools.html">Tools</a></li></ul></div><div><h2>Media</h2><ul><li><a 
href="https://twitter.com/theapachetomcat";>Twitter</a></li><li><a 
href="https://www.youtube.com/c/ApacheTomcatOfficial";>YouTube</a></li><li><a 
href="https://b
 logs.apache.org/tomcat/">Blog</a></li></ul></div><div><h2>Misc</h2><ul><li><a 
href="./whoweare.html">Who We Are</a></li><li><a 
href="https://www.redbubble.com/people/comdev/works/30885254-apache-tomcat";>Swag</a></li><li><a
 href="./heritage.html">Heritage</a></li><li><a 
href="http://www.apache.org";>Apache Home</a></li><li><a 
href="./resources.html">Resources</a></li><li><a 
href="./contact.html">Contact</a></li><li><a 
href="./legal.html">Legal</a></li><li><a 
href="https://www.apache.org/foundation/contributing.html";>Support 
Apache</a></li><li><a 
href="https://www.apache.org/foundation/sponsorship.html";>Sponsorship</a></li><li><a
 href="http://www.apache.org/foundation/thanks.html";>Thanks</a></li><li><a 
href="http://www.apache.org/licenses/";>License</a></li></ul></div></nav></div></div><div
 id="mainRight"><div id="content"><h2 style="display: none;">Content</h2><h3 
id="Apache_Tomcat_10.x_vulnerabilities">Apache Tomcat 10.x 
vulnerabilities</h3><div class="text">
     <p>This page lists all security vulnerabilities fixed in released versions
        of Apache Tomcat 10.x. Each vulnerability is given a
        <a href="security-impact.html">security impact rating</a> by the Apache
@@ -37,6 +35,8 @@
        <a href="security.html">Tomcat Security Team</a>. Thank you.
     </p>
 
+  </div><h3 id="Table_of_Contents">Table of Contents</h3><div class="text">
+    <ul><li><a href="#Fixed_in_Apache_Tomcat_10.0.16">Fixed in Apache Tomcat 
10.0.16</a></li><li><a href="#Fixed_in_Apache_Tomcat_10.1.0-M10">Fixed in 
Apache Tomcat 10.1.0-M10</a></li><li><a 
href="#Fixed_in_Apache_Tomcat_10.0.12">Fixed in Apache Tomcat 
10.0.12</a></li><li><a href="#Fixed_in_Apache_Tomcat_10.1.0-M6">Fixed in Apache 
Tomcat 10.1.0-M6</a></li><li><a href="#Fixed_in_Apache_Tomcat_10.0.7">Fixed in 
Apache Tomcat 10.0.7</a></li><li><a href="#Fixed_in_Apache_Tomcat_10.0.6">Fixed 
in Apache Tomcat 10.0.6</a></li><li><a 
href="#Fixed_in_Apache_Tomcat_10.0.5">Fixed in Apache Tomcat 
10.0.5</a></li><li><a href="#Fixed_in_Apache_Tomcat_10.0.4">Fixed in Apache 
Tomcat 10.0.4</a></li><li><a href="#Fixed_in_Apache_Tomcat_10.0.2">Fixed in 
Apache Tomcat 10.0.2</a></li><li><a 
href="#Fixed_in_Apache_Tomcat_10.0.0-M10">Fixed in Apache Tomcat 
10.0.0-M10</a></li><li><a href="#Fixed_in_Apache_Tomcat_10.0.0-M8">Fixed in 
Apache Tomcat 10.0.0-M8</a></li><li><a href="#Fixed_in_Apache_Tomcat_10.0.0-
 M7">Fixed in Apache Tomcat 10.0.0-M7</a></li><li><a 
href="#Fixed_in_Apache_Tomcat_10.0.0-M6">Fixed in Apache Tomcat 
10.0.0-M6</a></li><li><a href="#Fixed_in_Apache_Tomcat_10.0.0-M5">Fixed in 
Apache Tomcat 10.0.0-M5</a></li><li><a 
href="#Not_a_vulnerability_in_Tomcat">Not a vulnerability in 
Tomcat</a></li></ul>
   </div><h3 id="Fixed_in_Apache_Tomcat_10.0.16"><span class="pull-right">20 
January 2022</span> Fixed in Apache Tomcat 10.0.16</h3><div class="text">
 
     <p><i>Note: The issue below was fixed in Apache Tomcat 10.0.15 but the

Modified: tomcat/site/trunk/docs/security-3.html
URL: 
http://svn.apache.org/viewvc/tomcat/site/trunk/docs/security-3.html?rev=1897623&r1=1897622&r2=1897623&view=diff
==============================================================================
--- tomcat/site/trunk/docs/security-3.html (original)
+++ tomcat/site/trunk/docs/security-3.html Mon Jan 31 11:14:09 2022
@@ -1,7 +1,5 @@
 <!DOCTYPE html SYSTEM "about:legacy-compat">
-<html lang="en"><head><META http-equiv="Content-Type" content="text/html; 
charset=UTF-8"><meta name="viewport" content="width=device-width, 
initial-scale=1"><link href="res/css/tomcat.css" rel="stylesheet" 
type="text/css"><link href="res/css/fonts/fonts.css" rel="stylesheet" 
type="text/css"><title>Apache Tomcat&reg; - Apache Tomcat 3.x 
vulnerabilities</title><meta name="author" content="Apache Tomcat 
Project"></head><body><div id="wrapper"><header id="header"><div 
class="clearfix"><div class="menu-toggler pull-left" tabindex="1"><div 
class="hamburger"></div></div><a href="http://tomcat.apache.org/";><img 
class="tomcat-logo pull-left noPrint" alt="Tomcat Home" 
src="res/images/tomcat.png"></a><h1 class="pull-left">Apache 
Tomcat<sup>&reg;</sup></h1><div class="asf-logos pull-right"><a 
href="https://www.apache.org/foundation/contributing.html"; target="_blank" 
class="pull-left"><img 
src="https://www.apache.org/images/SupportApache-small.png"; class="support-asf" 
alt="Support Apache"></a><a
  href="http://www.apache.org/"; target="_blank" class="pull-left"><img 
src="res/images/asf_logo.svg" class="asf-logo" alt="The Apache Software 
Foundation"></a></div></div></header><main id="middle"><div><div 
id="mainLeft"><div id="nav-wrapper"><form 
action="https://www.google.com/search"; method="get"><div 
class="searchbox"><input value="tomcat.apache.org" name="sitesearch" 
type="hidden"><input aria-label="Search text" placeholder="Search&hellip;" 
required="required" name="q" id="query" 
type="search"><button>GO</button></div></form><nav><div><h2>Apache 
Tomcat</h2><ul><li><a href="./index.html">Home</a></li><li><a 
href="./taglibs.html">Taglibs</a></li><li><a href="./maven-plugin.html">Maven 
Plugin</a></li></ul></div><div><h2>Download</h2><ul><li><a 
href="./whichversion.html">Which version?</a></li><li><a 
href="https://tomcat.apache.org/download-10.cgi";>Tomcat 10</a></li><li><a 
href="https://tomcat.apache.org/download-90.cgi";>Tomcat 9</a></li><li><a 
href="https://tomcat.apache.org/downl
 oad-80.cgi">Tomcat 8</a></li><li><a 
href="https://tomcat.apache.org/download-migration.cgi";>Tomcat Migration Tool 
for Jakarta EE</a></li><li><a 
href="https://tomcat.apache.org/download-connectors.cgi";>Tomcat 
Connectors</a></li><li><a 
href="https://tomcat.apache.org/download-native.cgi";>Tomcat 
Native</a></li><li><a 
href="https://tomcat.apache.org/download-taglibs.cgi";>Taglibs</a></li><li><a 
href="https://archive.apache.org/dist/tomcat/";>Archives</a></li></ul></div><div><h2>Documentation</h2><ul><li><a
 href="./tomcat-10.1-doc/index.html">Tomcat 10.1 (alpha)</a></li><li><a 
href="./tomcat-10.0-doc/index.html">Tomcat 10.0</a></li><li><a 
href="./tomcat-9.0-doc/index.html">Tomcat 9.0</a></li><li><a 
href="./tomcat-8.5-doc/index.html">Tomcat 8.5</a></li><li><a 
href="./connectors-doc/">Tomcat Connectors</a></li><li><a 
href="./native-doc/">Tomcat Native</a></li><li><a 
href="https://cwiki.apache.org/confluence/display/TOMCAT";>Wiki</a></li><li><a 
href="./migration.html">Migration Guide</a></li><
 li><a href="./presentations.html">Presentations</a></li><li><a 
href="https://cwiki.apache.org/confluence/x/Bi8lBg";>Specifications</a></li></ul></div><div><h2>Problems?</h2><ul><li><a
 href="./security.html">Security Reports</a></li><li><a 
href="./findhelp.html">Find help</a></li><li><a 
href="https://cwiki.apache.org/confluence/display/TOMCAT/FAQ";>FAQ</a></li><li><a
 href="./lists.html">Mailing Lists</a></li><li><a href="./bugreport.html">Bug 
Database</a></li><li><a href="./irc.html">IRC</a></li></ul></div><div><h2>Get 
Involved</h2><ul><li><a href="./getinvolved.html">Overview</a></li><li><a 
href="./source.html">Source code</a></li><li><a 
href="./ci.html">Buildbot</a></li><li><a 
href="https://cwiki.apache.org/confluence/x/vIPzBQ";>Translations</a></li><li><a 
href="./tools.html">Tools</a></li></ul></div><div><h2>Media</h2><ul><li><a 
href="https://twitter.com/theapachetomcat";>Twitter</a></li><li><a 
href="https://www.youtube.com/c/ApacheTomcatOfficial";>YouTube</a></li><li><a 
href="https://
 blogs.apache.org/tomcat/">Blog</a></li></ul></div><div><h2>Misc</h2><ul><li><a 
href="./whoweare.html">Who We Are</a></li><li><a 
href="https://www.redbubble.com/people/comdev/works/30885254-apache-tomcat";>Swag</a></li><li><a
 href="./heritage.html">Heritage</a></li><li><a 
href="http://www.apache.org";>Apache Home</a></li><li><a 
href="./resources.html">Resources</a></li><li><a 
href="./contact.html">Contact</a></li><li><a 
href="./legal.html">Legal</a></li><li><a 
href="https://www.apache.org/foundation/contributing.html";>Support 
Apache</a></li><li><a 
href="https://www.apache.org/foundation/sponsorship.html";>Sponsorship</a></li><li><a
 href="http://www.apache.org/foundation/thanks.html";>Thanks</a></li><li><a 
href="http://www.apache.org/licenses/";>License</a></li></ul></div></nav></div></div><div
 id="mainRight"><div id="content"><h2 style="display: none;">Content</h2><h3 
id="Table_of_Contents">Table of Contents</h3><div class="text">
-<ul><li><a href="#Apache_Tomcat_3.x_vulnerabilities">Apache Tomcat 3.x 
vulnerabilities</a></li><li><a href="#Not_fixed_in_Apache_Tomcat_3.x">Not fixed 
in Apache Tomcat 3.x</a></li><li><a href="#Fixed_in_Apache_Tomcat_3.3.2">Fixed 
in Apache Tomcat 3.3.2</a></li><li><a 
href="#Fixed_in_Apache_Tomcat_3.3.1a">Fixed in Apache Tomcat 
3.3.1a</a></li><li><a href="#Fixed_in_Apache_Tomcat_3.3.1">Fixed in Apache 
Tomcat 3.3.1</a></li><li><a href="#Fixed_in_Apache_Tomcat_3.3a">Fixed in Apache 
Tomcat 3.3a</a></li><li><a href="#Fixed_in_Apache_Tomcat_3.2.4">Fixed in Apache 
Tomcat 3.2.4</a></li><li><a href="#Fixed_in_Apache_Tomcat_3.2.2">Fixed in 
Apache Tomcat 3.2.2</a></li><li><a href="#Fixed_in_Apache_Tomcat_3.2">Fixed in 
Apache Tomcat 3.2</a></li><li><a href="#Fixed_in_Apache_Tomcat_3.1">Fixed in 
Apache Tomcat 3.1</a></li></ul>
-</div><h3 id="Apache_Tomcat_3.x_vulnerabilities">Apache Tomcat 3.x 
vulnerabilities</h3><div class="text">
+<html lang="en"><head><META http-equiv="Content-Type" content="text/html; 
charset=UTF-8"><meta name="viewport" content="width=device-width, 
initial-scale=1"><link href="res/css/tomcat.css" rel="stylesheet" 
type="text/css"><link href="res/css/fonts/fonts.css" rel="stylesheet" 
type="text/css"><title>Apache Tomcat&reg; - Apache Tomcat 3.x 
vulnerabilities</title><meta name="author" content="Apache Tomcat 
Project"></head><body><div id="wrapper"><header id="header"><div 
class="clearfix"><div class="menu-toggler pull-left" tabindex="1"><div 
class="hamburger"></div></div><a href="http://tomcat.apache.org/";><img 
class="tomcat-logo pull-left noPrint" alt="Tomcat Home" 
src="res/images/tomcat.png"></a><h1 class="pull-left">Apache 
Tomcat<sup>&reg;</sup></h1><div class="asf-logos pull-right"><a 
href="https://www.apache.org/foundation/contributing.html"; target="_blank" 
class="pull-left"><img 
src="https://www.apache.org/images/SupportApache-small.png"; class="support-asf" 
alt="Support Apache"></a><a
  href="http://www.apache.org/"; target="_blank" class="pull-left"><img 
src="res/images/asf_logo.svg" class="asf-logo" alt="The Apache Software 
Foundation"></a></div></div></header><main id="middle"><div><div 
id="mainLeft"><div id="nav-wrapper"><form 
action="https://www.google.com/search"; method="get"><div 
class="searchbox"><input value="tomcat.apache.org" name="sitesearch" 
type="hidden"><input aria-label="Search text" placeholder="Search&hellip;" 
required="required" name="q" id="query" 
type="search"><button>GO</button></div></form><nav><div><h2>Apache 
Tomcat</h2><ul><li><a href="./index.html">Home</a></li><li><a 
href="./taglibs.html">Taglibs</a></li><li><a href="./maven-plugin.html">Maven 
Plugin</a></li></ul></div><div><h2>Download</h2><ul><li><a 
href="./whichversion.html">Which version?</a></li><li><a 
href="https://tomcat.apache.org/download-10.cgi";>Tomcat 10</a></li><li><a 
href="https://tomcat.apache.org/download-90.cgi";>Tomcat 9</a></li><li><a 
href="https://tomcat.apache.org/downl
 oad-80.cgi">Tomcat 8</a></li><li><a 
href="https://tomcat.apache.org/download-migration.cgi";>Tomcat Migration Tool 
for Jakarta EE</a></li><li><a 
href="https://tomcat.apache.org/download-connectors.cgi";>Tomcat 
Connectors</a></li><li><a 
href="https://tomcat.apache.org/download-native.cgi";>Tomcat 
Native</a></li><li><a 
href="https://tomcat.apache.org/download-taglibs.cgi";>Taglibs</a></li><li><a 
href="https://archive.apache.org/dist/tomcat/";>Archives</a></li></ul></div><div><h2>Documentation</h2><ul><li><a
 href="./tomcat-10.1-doc/index.html">Tomcat 10.1 (alpha)</a></li><li><a 
href="./tomcat-10.0-doc/index.html">Tomcat 10.0</a></li><li><a 
href="./tomcat-9.0-doc/index.html">Tomcat 9.0</a></li><li><a 
href="./tomcat-8.5-doc/index.html">Tomcat 8.5</a></li><li><a 
href="./connectors-doc/">Tomcat Connectors</a></li><li><a 
href="./native-doc/">Tomcat Native</a></li><li><a 
href="https://cwiki.apache.org/confluence/display/TOMCAT";>Wiki</a></li><li><a 
href="./migration.html">Migration Guide</a></li><
 li><a href="./presentations.html">Presentations</a></li><li><a 
href="https://cwiki.apache.org/confluence/x/Bi8lBg";>Specifications</a></li></ul></div><div><h2>Problems?</h2><ul><li><a
 href="./security.html">Security Reports</a></li><li><a 
href="./findhelp.html">Find help</a></li><li><a 
href="https://cwiki.apache.org/confluence/display/TOMCAT/FAQ";>FAQ</a></li><li><a
 href="./lists.html">Mailing Lists</a></li><li><a href="./bugreport.html">Bug 
Database</a></li><li><a href="./irc.html">IRC</a></li></ul></div><div><h2>Get 
Involved</h2><ul><li><a href="./getinvolved.html">Overview</a></li><li><a 
href="./source.html">Source code</a></li><li><a 
href="./ci.html">Buildbot</a></li><li><a 
href="https://cwiki.apache.org/confluence/x/vIPzBQ";>Translations</a></li><li><a 
href="./tools.html">Tools</a></li></ul></div><div><h2>Media</h2><ul><li><a 
href="https://twitter.com/theapachetomcat";>Twitter</a></li><li><a 
href="https://www.youtube.com/c/ApacheTomcatOfficial";>YouTube</a></li><li><a 
href="https://
 blogs.apache.org/tomcat/">Blog</a></li></ul></div><div><h2>Misc</h2><ul><li><a 
href="./whoweare.html">Who We Are</a></li><li><a 
href="https://www.redbubble.com/people/comdev/works/30885254-apache-tomcat";>Swag</a></li><li><a
 href="./heritage.html">Heritage</a></li><li><a 
href="http://www.apache.org";>Apache Home</a></li><li><a 
href="./resources.html">Resources</a></li><li><a 
href="./contact.html">Contact</a></li><li><a 
href="./legal.html">Legal</a></li><li><a 
href="https://www.apache.org/foundation/contributing.html";>Support 
Apache</a></li><li><a 
href="https://www.apache.org/foundation/sponsorship.html";>Sponsorship</a></li><li><a
 href="http://www.apache.org/foundation/thanks.html";>Thanks</a></li><li><a 
href="http://www.apache.org/licenses/";>License</a></li></ul></div></nav></div></div><div
 id="mainRight"><div id="content"><h2 style="display: none;">Content</h2><h3 
id="Apache_Tomcat_3.x_vulnerabilities">Apache Tomcat 3.x 
vulnerabilities</h3><div class="text">
     <p>This page lists all security vulnerabilities fixed in released versions
        of Apache Tomcat 3.x. Each vulnerability is given a
        <a href="security-impact.html">security impact rating</a> by the Apache
@@ -10,13 +8,15 @@
        is known to affect, and where a flaw has not been verified list the
        version with a question mark.</p>
 
-    <p>Please note that Tomcat 3 is no longer supported. Further 
vulnerabilities
-       in the 3.x branches will not be fixed. Users should upgrade to 7.x or
-       later to obtain security fixes.</p>
+    <p><strong>Please note that Tomcat 3 is no longer supported. Further
+       vulnerabilities in the 3.x branches will not be fixed. Users should 
upgrade
+       to 8.5.x or later to obtain security fixes.</strong></p>
 
     <p>Please send comments or corrections for these vulnerabilities to the
        <a href="security.html">Tomcat Security Team</a>.</p>
 
+  </div><h3 id="Table_of_Contents">Table of Contents</h3><div class="text">
+    <ul><li><a href="#Not_fixed_in_Apache_Tomcat_3.x">Not fixed in Apache 
Tomcat 3.x</a></li><li><a href="#Fixed_in_Apache_Tomcat_3.3.2">Fixed in Apache 
Tomcat 3.3.2</a></li><li><a href="#Fixed_in_Apache_Tomcat_3.3.1a">Fixed in 
Apache Tomcat 3.3.1a</a></li><li><a href="#Fixed_in_Apache_Tomcat_3.3.1">Fixed 
in Apache Tomcat 3.3.1</a></li><li><a href="#Fixed_in_Apache_Tomcat_3.3a">Fixed 
in Apache Tomcat 3.3a</a></li><li><a href="#Fixed_in_Apache_Tomcat_3.2.4">Fixed 
in Apache Tomcat 3.2.4</a></li><li><a 
href="#Fixed_in_Apache_Tomcat_3.2.2">Fixed in Apache Tomcat 
3.2.2</a></li><li><a href="#Fixed_in_Apache_Tomcat_3.2">Fixed in Apache Tomcat 
3.2</a></li><li><a href="#Fixed_in_Apache_Tomcat_3.1">Fixed in Apache Tomcat 
3.1</a></li></ul>
   </div><h3 id="Not_fixed_in_Apache_Tomcat_3.x">Not fixed in Apache Tomcat 
3.x</h3><div class="text">
     <p><strong>Important: Denial of service</strong>
        <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0808"; 
rel="nofollow">CVE-2005-0808</a></p>

Modified: tomcat/site/trunk/docs/security-4.html
URL: 
http://svn.apache.org/viewvc/tomcat/site/trunk/docs/security-4.html?rev=1897623&r1=1897622&r2=1897623&view=diff
==============================================================================
--- tomcat/site/trunk/docs/security-4.html (original)
+++ tomcat/site/trunk/docs/security-4.html Mon Jan 31 11:14:09 2022
@@ -1,7 +1,5 @@
 <!DOCTYPE html SYSTEM "about:legacy-compat">
-<html lang="en"><head><META http-equiv="Content-Type" content="text/html; 
charset=UTF-8"><meta name="viewport" content="width=device-width, 
initial-scale=1"><link href="res/css/tomcat.css" rel="stylesheet" 
type="text/css"><link href="res/css/fonts/fonts.css" rel="stylesheet" 
type="text/css"><title>Apache Tomcat&reg; - Apache Tomcat 4.x 
vulnerabilities</title><meta name="author" content="Apache Tomcat 
Project"></head><body><div id="wrapper"><header id="header"><div 
class="clearfix"><div class="menu-toggler pull-left" tabindex="1"><div 
class="hamburger"></div></div><a href="http://tomcat.apache.org/";><img 
class="tomcat-logo pull-left noPrint" alt="Tomcat Home" 
src="res/images/tomcat.png"></a><h1 class="pull-left">Apache 
Tomcat<sup>&reg;</sup></h1><div class="asf-logos pull-right"><a 
href="https://www.apache.org/foundation/contributing.html"; target="_blank" 
class="pull-left"><img 
src="https://www.apache.org/images/SupportApache-small.png"; class="support-asf" 
alt="Support Apache"></a><a
  href="http://www.apache.org/"; target="_blank" class="pull-left"><img 
src="res/images/asf_logo.svg" class="asf-logo" alt="The Apache Software 
Foundation"></a></div></div></header><main id="middle"><div><div 
id="mainLeft"><div id="nav-wrapper"><form 
action="https://www.google.com/search"; method="get"><div 
class="searchbox"><input value="tomcat.apache.org" name="sitesearch" 
type="hidden"><input aria-label="Search text" placeholder="Search&hellip;" 
required="required" name="q" id="query" 
type="search"><button>GO</button></div></form><nav><div><h2>Apache 
Tomcat</h2><ul><li><a href="./index.html">Home</a></li><li><a 
href="./taglibs.html">Taglibs</a></li><li><a href="./maven-plugin.html">Maven 
Plugin</a></li></ul></div><div><h2>Download</h2><ul><li><a 
href="./whichversion.html">Which version?</a></li><li><a 
href="https://tomcat.apache.org/download-10.cgi";>Tomcat 10</a></li><li><a 
href="https://tomcat.apache.org/download-90.cgi";>Tomcat 9</a></li><li><a 
href="https://tomcat.apache.org/downl
 oad-80.cgi">Tomcat 8</a></li><li><a 
href="https://tomcat.apache.org/download-migration.cgi";>Tomcat Migration Tool 
for Jakarta EE</a></li><li><a 
href="https://tomcat.apache.org/download-connectors.cgi";>Tomcat 
Connectors</a></li><li><a 
href="https://tomcat.apache.org/download-native.cgi";>Tomcat 
Native</a></li><li><a 
href="https://tomcat.apache.org/download-taglibs.cgi";>Taglibs</a></li><li><a 
href="https://archive.apache.org/dist/tomcat/";>Archives</a></li></ul></div><div><h2>Documentation</h2><ul><li><a
 href="./tomcat-10.1-doc/index.html">Tomcat 10.1 (alpha)</a></li><li><a 
href="./tomcat-10.0-doc/index.html">Tomcat 10.0</a></li><li><a 
href="./tomcat-9.0-doc/index.html">Tomcat 9.0</a></li><li><a 
href="./tomcat-8.5-doc/index.html">Tomcat 8.5</a></li><li><a 
href="./connectors-doc/">Tomcat Connectors</a></li><li><a 
href="./native-doc/">Tomcat Native</a></li><li><a 
href="https://cwiki.apache.org/confluence/display/TOMCAT";>Wiki</a></li><li><a 
href="./migration.html">Migration Guide</a></li><
 li><a href="./presentations.html">Presentations</a></li><li><a 
href="https://cwiki.apache.org/confluence/x/Bi8lBg";>Specifications</a></li></ul></div><div><h2>Problems?</h2><ul><li><a
 href="./security.html">Security Reports</a></li><li><a 
href="./findhelp.html">Find help</a></li><li><a 
href="https://cwiki.apache.org/confluence/display/TOMCAT/FAQ";>FAQ</a></li><li><a
 href="./lists.html">Mailing Lists</a></li><li><a href="./bugreport.html">Bug 
Database</a></li><li><a href="./irc.html">IRC</a></li></ul></div><div><h2>Get 
Involved</h2><ul><li><a href="./getinvolved.html">Overview</a></li><li><a 
href="./source.html">Source code</a></li><li><a 
href="./ci.html">Buildbot</a></li><li><a 
href="https://cwiki.apache.org/confluence/x/vIPzBQ";>Translations</a></li><li><a 
href="./tools.html">Tools</a></li></ul></div><div><h2>Media</h2><ul><li><a 
href="https://twitter.com/theapachetomcat";>Twitter</a></li><li><a 
href="https://www.youtube.com/c/ApacheTomcatOfficial";>YouTube</a></li><li><a 
href="https://
 blogs.apache.org/tomcat/">Blog</a></li></ul></div><div><h2>Misc</h2><ul><li><a 
href="./whoweare.html">Who We Are</a></li><li><a 
href="https://www.redbubble.com/people/comdev/works/30885254-apache-tomcat";>Swag</a></li><li><a
 href="./heritage.html">Heritage</a></li><li><a 
href="http://www.apache.org";>Apache Home</a></li><li><a 
href="./resources.html">Resources</a></li><li><a 
href="./contact.html">Contact</a></li><li><a 
href="./legal.html">Legal</a></li><li><a 
href="https://www.apache.org/foundation/contributing.html";>Support 
Apache</a></li><li><a 
href="https://www.apache.org/foundation/sponsorship.html";>Sponsorship</a></li><li><a
 href="http://www.apache.org/foundation/thanks.html";>Thanks</a></li><li><a 
href="http://www.apache.org/licenses/";>License</a></li></ul></div></nav></div></div><div
 id="mainRight"><div id="content"><h2 style="display: none;">Content</h2><h3 
id="Table_of_Contents">Table of Contents</h3><div class="text">
-<ul><li><a href="#Apache_Tomcat_4.x_vulnerabilities">Apache Tomcat 4.x 
vulnerabilities</a></li><li><a 
href="#Will_not_be_fixed_in_Apache_Tomcat_4.1.x">Will not be fixed in Apache 
Tomcat 4.1.x</a></li><li><a href="#Fixed_in_Apache_Tomcat_4.1.40">Fixed in 
Apache Tomcat 4.1.40</a></li><li><a href="#Fixed_in_Apache_Tomcat_4.1.39">Fixed 
in Apache Tomcat 4.1.39</a></li><li><a 
href="#Fixed_in_Apache_Tomcat_4.1.37">Fixed in Apache Tomcat 
4.1.37</a></li><li><a href="#Fixed_in_Apache_Tomcat_4.1.36">Fixed in Apache 
Tomcat 4.1.36</a></li><li><a href="#Fixed_in_Apache_Tomcat_4.1.35">Fixed in 
Apache Tomcat 4.1.35</a></li><li><a href="#Fixed_in_Apache_Tomcat_4.1.32">Fixed 
in Apache Tomcat 4.1.32</a></li><li><a 
href="#Fixed_in_Apache_Tomcat_4.1.29">Fixed in Apache Tomcat 
4.1.29</a></li><li><a href="#Fixed_in_Apache_Tomcat_4.1.13,_4.0.6">Fixed in 
Apache Tomcat 4.1.13, 4.0.6</a></li><li><a 
href="#Fixed_in_Apache_Tomcat_4.1.12,_4.0.5">Fixed in Apache Tomcat 4.1.12, 
4.0.5</a></li><li><a href="#Fixed_in
 _Apache_Tomcat_4.1.3">Fixed in Apache Tomcat 4.1.3</a></li><li><a 
href="#Fixed_in_Apache_Tomcat_4.1.0">Fixed in Apache Tomcat 
4.1.0</a></li><li><a href="#Fixed_in_Apache_Tomcat_4.0.2">Fixed in Apache 
Tomcat 4.0.2</a></li><li><a href="#Fixed_in_Apache_Tomcat_4.0.0">Fixed in 
Apache Tomcat 4.0.0</a></li><li><a href="#Unverified">Unverified</a></li><li><a 
href="#Not_a_vulnerability_in_Tomcat">Not a vulnerability in 
Tomcat</a></li></ul>
-</div><h3 id="Apache_Tomcat_4.x_vulnerabilities">Apache Tomcat 4.x 
vulnerabilities</h3><div class="text">
+<html lang="en"><head><META http-equiv="Content-Type" content="text/html; 
charset=UTF-8"><meta name="viewport" content="width=device-width, 
initial-scale=1"><link href="res/css/tomcat.css" rel="stylesheet" 
type="text/css"><link href="res/css/fonts/fonts.css" rel="stylesheet" 
type="text/css"><title>Apache Tomcat&reg; - Apache Tomcat 4.x 
vulnerabilities</title><meta name="author" content="Apache Tomcat 
Project"></head><body><div id="wrapper"><header id="header"><div 
class="clearfix"><div class="menu-toggler pull-left" tabindex="1"><div 
class="hamburger"></div></div><a href="http://tomcat.apache.org/";><img 
class="tomcat-logo pull-left noPrint" alt="Tomcat Home" 
src="res/images/tomcat.png"></a><h1 class="pull-left">Apache 
Tomcat<sup>&reg;</sup></h1><div class="asf-logos pull-right"><a 
href="https://www.apache.org/foundation/contributing.html"; target="_blank" 
class="pull-left"><img 
src="https://www.apache.org/images/SupportApache-small.png"; class="support-asf" 
alt="Support Apache"></a><a
  href="http://www.apache.org/"; target="_blank" class="pull-left"><img 
src="res/images/asf_logo.svg" class="asf-logo" alt="The Apache Software 
Foundation"></a></div></div></header><main id="middle"><div><div 
id="mainLeft"><div id="nav-wrapper"><form 
action="https://www.google.com/search"; method="get"><div 
class="searchbox"><input value="tomcat.apache.org" name="sitesearch" 
type="hidden"><input aria-label="Search text" placeholder="Search&hellip;" 
required="required" name="q" id="query" 
type="search"><button>GO</button></div></form><nav><div><h2>Apache 
Tomcat</h2><ul><li><a href="./index.html">Home</a></li><li><a 
href="./taglibs.html">Taglibs</a></li><li><a href="./maven-plugin.html">Maven 
Plugin</a></li></ul></div><div><h2>Download</h2><ul><li><a 
href="./whichversion.html">Which version?</a></li><li><a 
href="https://tomcat.apache.org/download-10.cgi";>Tomcat 10</a></li><li><a 
href="https://tomcat.apache.org/download-90.cgi";>Tomcat 9</a></li><li><a 
href="https://tomcat.apache.org/downl
 oad-80.cgi">Tomcat 8</a></li><li><a 
href="https://tomcat.apache.org/download-migration.cgi";>Tomcat Migration Tool 
for Jakarta EE</a></li><li><a 
href="https://tomcat.apache.org/download-connectors.cgi";>Tomcat 
Connectors</a></li><li><a 
href="https://tomcat.apache.org/download-native.cgi";>Tomcat 
Native</a></li><li><a 
href="https://tomcat.apache.org/download-taglibs.cgi";>Taglibs</a></li><li><a 
href="https://archive.apache.org/dist/tomcat/";>Archives</a></li></ul></div><div><h2>Documentation</h2><ul><li><a
 href="./tomcat-10.1-doc/index.html">Tomcat 10.1 (alpha)</a></li><li><a 
href="./tomcat-10.0-doc/index.html">Tomcat 10.0</a></li><li><a 
href="./tomcat-9.0-doc/index.html">Tomcat 9.0</a></li><li><a 
href="./tomcat-8.5-doc/index.html">Tomcat 8.5</a></li><li><a 
href="./connectors-doc/">Tomcat Connectors</a></li><li><a 
href="./native-doc/">Tomcat Native</a></li><li><a 
href="https://cwiki.apache.org/confluence/display/TOMCAT";>Wiki</a></li><li><a 
href="./migration.html">Migration Guide</a></li><
 li><a href="./presentations.html">Presentations</a></li><li><a 
href="https://cwiki.apache.org/confluence/x/Bi8lBg";>Specifications</a></li></ul></div><div><h2>Problems?</h2><ul><li><a
 href="./security.html">Security Reports</a></li><li><a 
href="./findhelp.html">Find help</a></li><li><a 
href="https://cwiki.apache.org/confluence/display/TOMCAT/FAQ";>FAQ</a></li><li><a
 href="./lists.html">Mailing Lists</a></li><li><a href="./bugreport.html">Bug 
Database</a></li><li><a href="./irc.html">IRC</a></li></ul></div><div><h2>Get 
Involved</h2><ul><li><a href="./getinvolved.html">Overview</a></li><li><a 
href="./source.html">Source code</a></li><li><a 
href="./ci.html">Buildbot</a></li><li><a 
href="https://cwiki.apache.org/confluence/x/vIPzBQ";>Translations</a></li><li><a 
href="./tools.html">Tools</a></li></ul></div><div><h2>Media</h2><ul><li><a 
href="https://twitter.com/theapachetomcat";>Twitter</a></li><li><a 
href="https://www.youtube.com/c/ApacheTomcatOfficial";>YouTube</a></li><li><a 
href="https://
 blogs.apache.org/tomcat/">Blog</a></li></ul></div><div><h2>Misc</h2><ul><li><a 
href="./whoweare.html">Who We Are</a></li><li><a 
href="https://www.redbubble.com/people/comdev/works/30885254-apache-tomcat";>Swag</a></li><li><a
 href="./heritage.html">Heritage</a></li><li><a 
href="http://www.apache.org";>Apache Home</a></li><li><a 
href="./resources.html">Resources</a></li><li><a 
href="./contact.html">Contact</a></li><li><a 
href="./legal.html">Legal</a></li><li><a 
href="https://www.apache.org/foundation/contributing.html";>Support 
Apache</a></li><li><a 
href="https://www.apache.org/foundation/sponsorship.html";>Sponsorship</a></li><li><a
 href="http://www.apache.org/foundation/thanks.html";>Thanks</a></li><li><a 
href="http://www.apache.org/licenses/";>License</a></li></ul></div></nav></div></div><div
 id="mainRight"><div id="content"><h2 style="display: none;">Content</h2><h3 
id="Apache_Tomcat_4.x_vulnerabilities">Apache Tomcat 4.x 
vulnerabilities</h3><div class="text">
     <p>This page lists all security vulnerabilities fixed in released versions
        of Apache Tomcat 4.x. Each vulnerability is given a
        <a href="security-impact.html">security impact rating</a> by the Apache
@@ -14,13 +12,16 @@
        but have either been incorrectly reported against Tomcat or where Tomcat
        provides a workaround are listed at the end of this page.</p>
 
-    <p>Please note that Tomcat 4.0.x and 4.1.x are no longer supported. Further
-       vulnerabilities in the 4.0.x and 4.1.x branches will not be fixed. Users
-       should upgrade to 7.x or later to obtain security fixes.</p>
+    <p><strong>Please note that Tomcat 4.0.x and 4.1.x are no longer supported.
+       Further vulnerabilities in the 4.0.x and 4.1.x branches will not be
+       fixed. Users should upgrade to 8.5.x or later to obtain security fixes.
+       </strong></p>
 
     <p>Please send comments or corrections for these vulnerabilities to the
        <a href="security.html">Tomcat Security Team</a>.</p>
 
+  </div><h3 id="Table_of_Contents">Table of Contents</h3><div class="text">
+    <ul><li><a href="#Will_not_be_fixed_in_Apache_Tomcat_4.1.x">Will not be 
fixed in Apache Tomcat 4.1.x</a></li><li><a 
href="#Fixed_in_Apache_Tomcat_4.1.40">Fixed in Apache Tomcat 
4.1.40</a></li><li><a href="#Fixed_in_Apache_Tomcat_4.1.39">Fixed in Apache 
Tomcat 4.1.39</a></li><li><a href="#Fixed_in_Apache_Tomcat_4.1.37">Fixed in 
Apache Tomcat 4.1.37</a></li><li><a href="#Fixed_in_Apache_Tomcat_4.1.36">Fixed 
in Apache Tomcat 4.1.36</a></li><li><a 
href="#Fixed_in_Apache_Tomcat_4.1.35">Fixed in Apache Tomcat 
4.1.35</a></li><li><a href="#Fixed_in_Apache_Tomcat_4.1.32">Fixed in Apache 
Tomcat 4.1.32</a></li><li><a href="#Fixed_in_Apache_Tomcat_4.1.29">Fixed in 
Apache Tomcat 4.1.29</a></li><li><a 
href="#Fixed_in_Apache_Tomcat_4.1.13,_4.0.6">Fixed in Apache Tomcat 4.1.13, 
4.0.6</a></li><li><a href="#Fixed_in_Apache_Tomcat_4.1.12,_4.0.5">Fixed in 
Apache Tomcat 4.1.12, 4.0.5</a></li><li><a 
href="#Fixed_in_Apache_Tomcat_4.1.3">Fixed in Apache Tomcat 
4.1.3</a></li><li><a href="#Fixed_in_Apach
 e_Tomcat_4.1.0">Fixed in Apache Tomcat 4.1.0</a></li><li><a 
href="#Fixed_in_Apache_Tomcat_4.0.2">Fixed in Apache Tomcat 
4.0.2</a></li><li><a href="#Fixed_in_Apache_Tomcat_4.0.0">Fixed in Apache 
Tomcat 4.0.0</a></li><li><a href="#Unverified">Unverified</a></li><li><a 
href="#Not_a_vulnerability_in_Tomcat">Not a vulnerability in 
Tomcat</a></li></ul>
   </div><h3 id="Will_not_be_fixed_in_Apache_Tomcat_4.1.x">Will not be fixed in 
Apache Tomcat 4.1.x</h3><div class="text">
     <p><strong>Moderate: Information disclosure</strong>
        <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-4836"; 
rel="nofollow">CVE-2005-4836</a></p>

Modified: tomcat/site/trunk/docs/security-5.html
URL: 
http://svn.apache.org/viewvc/tomcat/site/trunk/docs/security-5.html?rev=1897623&r1=1897622&r2=1897623&view=diff
==============================================================================
--- tomcat/site/trunk/docs/security-5.html (original)
+++ tomcat/site/trunk/docs/security-5.html Mon Jan 31 11:14:09 2022
@@ -1,7 +1,5 @@
 <!DOCTYPE html SYSTEM "about:legacy-compat">
-<html lang="en"><head><META http-equiv="Content-Type" content="text/html; 
charset=UTF-8"><meta name="viewport" content="width=device-width, 
initial-scale=1"><link href="res/css/tomcat.css" rel="stylesheet" 
type="text/css"><link href="res/css/fonts/fonts.css" rel="stylesheet" 
type="text/css"><title>Apache Tomcat&reg; - Apache Tomcat 5 
vulnerabilities</title><meta name="author" content="Apache Tomcat 
Project"></head><body><div id="wrapper"><header id="header"><div 
class="clearfix"><div class="menu-toggler pull-left" tabindex="1"><div 
class="hamburger"></div></div><a href="http://tomcat.apache.org/";><img 
class="tomcat-logo pull-left noPrint" alt="Tomcat Home" 
src="res/images/tomcat.png"></a><h1 class="pull-left">Apache 
Tomcat<sup>&reg;</sup></h1><div class="asf-logos pull-right"><a 
href="https://www.apache.org/foundation/contributing.html"; target="_blank" 
class="pull-left"><img 
src="https://www.apache.org/images/SupportApache-small.png"; class="support-asf" 
alt="Support Apache"></a><a h
 ref="http://www.apache.org/"; target="_blank" class="pull-left"><img 
src="res/images/asf_logo.svg" class="asf-logo" alt="The Apache Software 
Foundation"></a></div></div></header><main id="middle"><div><div 
id="mainLeft"><div id="nav-wrapper"><form 
action="https://www.google.com/search"; method="get"><div 
class="searchbox"><input value="tomcat.apache.org" name="sitesearch" 
type="hidden"><input aria-label="Search text" placeholder="Search&hellip;" 
required="required" name="q" id="query" 
type="search"><button>GO</button></div></form><nav><div><h2>Apache 
Tomcat</h2><ul><li><a href="./index.html">Home</a></li><li><a 
href="./taglibs.html">Taglibs</a></li><li><a href="./maven-plugin.html">Maven 
Plugin</a></li></ul></div><div><h2>Download</h2><ul><li><a 
href="./whichversion.html">Which version?</a></li><li><a 
href="https://tomcat.apache.org/download-10.cgi";>Tomcat 10</a></li><li><a 
href="https://tomcat.apache.org/download-90.cgi";>Tomcat 9</a></li><li><a 
href="https://tomcat.apache.org/downloa
 d-80.cgi">Tomcat 8</a></li><li><a 
href="https://tomcat.apache.org/download-migration.cgi";>Tomcat Migration Tool 
for Jakarta EE</a></li><li><a 
href="https://tomcat.apache.org/download-connectors.cgi";>Tomcat 
Connectors</a></li><li><a 
href="https://tomcat.apache.org/download-native.cgi";>Tomcat 
Native</a></li><li><a 
href="https://tomcat.apache.org/download-taglibs.cgi";>Taglibs</a></li><li><a 
href="https://archive.apache.org/dist/tomcat/";>Archives</a></li></ul></div><div><h2>Documentation</h2><ul><li><a
 href="./tomcat-10.1-doc/index.html">Tomcat 10.1 (alpha)</a></li><li><a 
href="./tomcat-10.0-doc/index.html">Tomcat 10.0</a></li><li><a 
href="./tomcat-9.0-doc/index.html">Tomcat 9.0</a></li><li><a 
href="./tomcat-8.5-doc/index.html">Tomcat 8.5</a></li><li><a 
href="./connectors-doc/">Tomcat Connectors</a></li><li><a 
href="./native-doc/">Tomcat Native</a></li><li><a 
href="https://cwiki.apache.org/confluence/display/TOMCAT";>Wiki</a></li><li><a 
href="./migration.html">Migration Guide</a></li><li
 ><a href="./presentations.html">Presentations</a></li><li><a 
 >href="https://cwiki.apache.org/confluence/x/Bi8lBg";>Specifications</a></li></ul></div><div><h2>Problems?</h2><ul><li><a
 > href="./security.html">Security Reports</a></li><li><a 
 >href="./findhelp.html">Find help</a></li><li><a 
 >href="https://cwiki.apache.org/confluence/display/TOMCAT/FAQ";>FAQ</a></li><li><a
 > href="./lists.html">Mailing Lists</a></li><li><a href="./bugreport.html">Bug 
 >Database</a></li><li><a href="./irc.html">IRC</a></li></ul></div><div><h2>Get 
 >Involved</h2><ul><li><a href="./getinvolved.html">Overview</a></li><li><a 
 >href="./source.html">Source code</a></li><li><a 
 >href="./ci.html">Buildbot</a></li><li><a 
 >href="https://cwiki.apache.org/confluence/x/vIPzBQ";>Translations</a></li><li><a
 > href="./tools.html">Tools</a></li></ul></div><div><h2>Media</h2><ul><li><a 
 >href="https://twitter.com/theapachetomcat";>Twitter</a></li><li><a 
 >href="https://www.youtube.com/c/ApacheTomcatOfficial";>YouTube</a></li><li><a 
 >href="https://bl
 ogs.apache.org/tomcat/">Blog</a></li></ul></div><div><h2>Misc</h2><ul><li><a 
href="./whoweare.html">Who We Are</a></li><li><a 
href="https://www.redbubble.com/people/comdev/works/30885254-apache-tomcat";>Swag</a></li><li><a
 href="./heritage.html">Heritage</a></li><li><a 
href="http://www.apache.org";>Apache Home</a></li><li><a 
href="./resources.html">Resources</a></li><li><a 
href="./contact.html">Contact</a></li><li><a 
href="./legal.html">Legal</a></li><li><a 
href="https://www.apache.org/foundation/contributing.html";>Support 
Apache</a></li><li><a 
href="https://www.apache.org/foundation/sponsorship.html";>Sponsorship</a></li><li><a
 href="http://www.apache.org/foundation/thanks.html";>Thanks</a></li><li><a 
href="http://www.apache.org/licenses/";>License</a></li></ul></div></nav></div></div><div
 id="mainRight"><div id="content"><h2 style="display: none;">Content</h2><h3 
id="Table_of_Contents">Table of Contents</h3><div class="text">
-<ul><li><a href="#Apache_Tomcat_5.x_vulnerabilities">Apache Tomcat 5.x 
vulnerabilities</a></li><li><a href="#Fixed_in_Apache_Tomcat_5.5.36">Fixed in 
Apache Tomcat 5.5.36</a></li><li><a href="#Fixed_in_Apache_Tomcat_5.5.35">Fixed 
in Apache Tomcat 5.5.35</a></li><li><a 
href="#Fixed_in_Apache_Tomcat_5.5.34">Fixed in Apache Tomcat 
5.5.34</a></li><li><a href="#Fixed_in_Apache_Tomcat_5.5.32">Fixed in Apache 
Tomcat 5.5.32</a></li><li><a href="#Fixed_in_Apache_Tomcat_5.5.30">Fixed in 
Apache Tomcat 5.5.30</a></li><li><a href="#Fixed_in_Apache_Tomcat_5.5.29">Fixed 
in Apache Tomcat 5.5.29</a></li><li><a 
href="#Fixed_in_Apache_Tomcat_5.5.28">Fixed in Apache Tomcat 
5.5.28</a></li><li><a href="#Fixed_in_Apache_Tomcat_5.5.27">Fixed in Apache 
Tomcat 5.5.27</a></li><li><a href="#Fixed_in_Apache_Tomcat_5.5.26">Fixed in 
Apache Tomcat 5.5.26</a></li><li><a 
href="#Fixed_in_Apache_Tomcat_5.5.25,_5.0.SVN">Fixed in Apache Tomcat 5.5.25, 
5.0.SVN</a></li><li><a href="#Fixed_in_Apache_Tomcat_5.5.24,_5.0.SVN">
 Fixed in Apache Tomcat 5.5.24, 5.0.SVN</a></li><li><a 
href="#Fixed_in_Apache_Tomcat_5.5.23,_5.0.SVN">Fixed in Apache Tomcat 5.5.23, 
5.0.SVN</a></li><li><a href="#Fixed_in_Apache_Tomcat_5.5.22,_5.0.SVN">Fixed in 
Apache Tomcat 5.5.22, 5.0.SVN</a></li><li><a 
href="#Fixed_in_Apache_Tomcat_5.5.21,_5.0.SVN">Fixed in Apache Tomcat 5.5.21, 
5.0.SVN</a></li><li><a href="#Fixed_in_Apache_Tomcat_5.5.21">Fixed in Apache 
Tomcat 5.5.21</a></li><li><a 
href="#Fixed_in_Apache_Tomcat_5.5.18,_5.0.SVN">Fixed in Apache Tomcat 5.5.18, 
5.0.SVN</a></li><li><a href="#Fixed_in_Apache_Tomcat_5.5.17,_5.0.SVN">Fixed in 
Apache Tomcat 5.5.17, 5.0.SVN</a></li><li><a 
href="#Fixed_in_Apache_Tomcat_5.5.16,_5.0.SVN">Fixed in Apache Tomcat 5.5.16, 
5.0.SVN</a></li><li><a href="#Fixed_in_Apache_Tomcat_5.5.13,_5.0.SVN">Fixed in 
Apache Tomcat 5.5.13, 5.0.SVN</a></li><li><a 
href="#Fixed_in_Apache_Tomcat_5.5.7,_5.0.SVN">Fixed in Apache Tomcat 5.5.7, 
5.0.SVN</a></li><li><a href="#Fixed_in_Apache_Tomcat_5.5.1">Fixed in Apache T
 omcat 5.5.1</a></li><li><a href="#Not_a_vulnerability_in_Tomcat">Not a 
vulnerability in Tomcat</a></li></ul>
-</div><h3 id="Apache_Tomcat_5.x_vulnerabilities">Apache Tomcat 5.x 
vulnerabilities</h3><div class="text">
+<html lang="en"><head><META http-equiv="Content-Type" content="text/html; 
charset=UTF-8"><meta name="viewport" content="width=device-width, 
initial-scale=1"><link href="res/css/tomcat.css" rel="stylesheet" 
type="text/css"><link href="res/css/fonts/fonts.css" rel="stylesheet" 
type="text/css"><title>Apache Tomcat&reg; - Apache Tomcat 5 
vulnerabilities</title><meta name="author" content="Apache Tomcat 
Project"></head><body><div id="wrapper"><header id="header"><div 
class="clearfix"><div class="menu-toggler pull-left" tabindex="1"><div 
class="hamburger"></div></div><a href="http://tomcat.apache.org/";><img 
class="tomcat-logo pull-left noPrint" alt="Tomcat Home" 
src="res/images/tomcat.png"></a><h1 class="pull-left">Apache 
Tomcat<sup>&reg;</sup></h1><div class="asf-logos pull-right"><a 
href="https://www.apache.org/foundation/contributing.html"; target="_blank" 
class="pull-left"><img 
src="https://www.apache.org/images/SupportApache-small.png"; class="support-asf" 
alt="Support Apache"></a><a h
 ref="http://www.apache.org/"; target="_blank" class="pull-left"><img 
src="res/images/asf_logo.svg" class="asf-logo" alt="The Apache Software 
Foundation"></a></div></div></header><main id="middle"><div><div 
id="mainLeft"><div id="nav-wrapper"><form 
action="https://www.google.com/search"; method="get"><div 
class="searchbox"><input value="tomcat.apache.org" name="sitesearch" 
type="hidden"><input aria-label="Search text" placeholder="Search&hellip;" 
required="required" name="q" id="query" 
type="search"><button>GO</button></div></form><nav><div><h2>Apache 
Tomcat</h2><ul><li><a href="./index.html">Home</a></li><li><a 
href="./taglibs.html">Taglibs</a></li><li><a href="./maven-plugin.html">Maven 
Plugin</a></li></ul></div><div><h2>Download</h2><ul><li><a 
href="./whichversion.html">Which version?</a></li><li><a 
href="https://tomcat.apache.org/download-10.cgi";>Tomcat 10</a></li><li><a 
href="https://tomcat.apache.org/download-90.cgi";>Tomcat 9</a></li><li><a 
href="https://tomcat.apache.org/downloa
 d-80.cgi">Tomcat 8</a></li><li><a 
href="https://tomcat.apache.org/download-migration.cgi";>Tomcat Migration Tool 
for Jakarta EE</a></li><li><a 
href="https://tomcat.apache.org/download-connectors.cgi";>Tomcat 
Connectors</a></li><li><a 
href="https://tomcat.apache.org/download-native.cgi";>Tomcat 
Native</a></li><li><a 
href="https://tomcat.apache.org/download-taglibs.cgi";>Taglibs</a></li><li><a 
href="https://archive.apache.org/dist/tomcat/";>Archives</a></li></ul></div><div><h2>Documentation</h2><ul><li><a
 href="./tomcat-10.1-doc/index.html">Tomcat 10.1 (alpha)</a></li><li><a 
href="./tomcat-10.0-doc/index.html">Tomcat 10.0</a></li><li><a 
href="./tomcat-9.0-doc/index.html">Tomcat 9.0</a></li><li><a 
href="./tomcat-8.5-doc/index.html">Tomcat 8.5</a></li><li><a 
href="./connectors-doc/">Tomcat Connectors</a></li><li><a 
href="./native-doc/">Tomcat Native</a></li><li><a 
href="https://cwiki.apache.org/confluence/display/TOMCAT";>Wiki</a></li><li><a 
href="./migration.html">Migration Guide</a></li><li
 ><a href="./presentations.html">Presentations</a></li><li><a 
 >href="https://cwiki.apache.org/confluence/x/Bi8lBg";>Specifications</a></li></ul></div><div><h2>Problems?</h2><ul><li><a
 > href="./security.html">Security Reports</a></li><li><a 
 >href="./findhelp.html">Find help</a></li><li><a 
 >href="https://cwiki.apache.org/confluence/display/TOMCAT/FAQ";>FAQ</a></li><li><a
 > href="./lists.html">Mailing Lists</a></li><li><a href="./bugreport.html">Bug 
 >Database</a></li><li><a href="./irc.html">IRC</a></li></ul></div><div><h2>Get 
 >Involved</h2><ul><li><a href="./getinvolved.html">Overview</a></li><li><a 
 >href="./source.html">Source code</a></li><li><a 
 >href="./ci.html">Buildbot</a></li><li><a 
 >href="https://cwiki.apache.org/confluence/x/vIPzBQ";>Translations</a></li><li><a
 > href="./tools.html">Tools</a></li></ul></div><div><h2>Media</h2><ul><li><a 
 >href="https://twitter.com/theapachetomcat";>Twitter</a></li><li><a 
 >href="https://www.youtube.com/c/ApacheTomcatOfficial";>YouTube</a></li><li><a 
 >href="https://bl
 ogs.apache.org/tomcat/">Blog</a></li></ul></div><div><h2>Misc</h2><ul><li><a 
href="./whoweare.html">Who We Are</a></li><li><a 
href="https://www.redbubble.com/people/comdev/works/30885254-apache-tomcat";>Swag</a></li><li><a
 href="./heritage.html">Heritage</a></li><li><a 
href="http://www.apache.org";>Apache Home</a></li><li><a 
href="./resources.html">Resources</a></li><li><a 
href="./contact.html">Contact</a></li><li><a 
href="./legal.html">Legal</a></li><li><a 
href="https://www.apache.org/foundation/contributing.html";>Support 
Apache</a></li><li><a 
href="https://www.apache.org/foundation/sponsorship.html";>Sponsorship</a></li><li><a
 href="http://www.apache.org/foundation/thanks.html";>Thanks</a></li><li><a 
href="http://www.apache.org/licenses/";>License</a></li></ul></div></nav></div></div><div
 id="mainRight"><div id="content"><h2 style="display: none;">Content</h2><h3 
id="Apache_Tomcat_5.x_vulnerabilities">Apache Tomcat 5.x 
vulnerabilities</h3><div class="text">
     <p>This page lists all security vulnerabilities fixed in released versions
        of Apache Tomcat 5.x. Each vulnerability is given a
        <a href="security-impact.html">security impact rating</a> by the Apache
@@ -14,11 +12,11 @@
        but have either been incorrectly reported against Tomcat or where Tomcat
        provides a workaround are listed at the end of this page.</p>
 
-    <p>Please note that Tomcat 5.0.x and 5.5.x are no longer supported. Further
-       vulnerabilities in the 5.0.x and 5.5.x branches will not be fixed. Users
-       should upgrade to 7.x or later to obtain security fixes. Vulnerabilities
-       fixed in Tomcat 5.5.26 onwards have not been assessed to determine if
-       they are present in the 5.0.x branch.</p>
+    <p><strong>Please note that Tomcat 5.0.x and 5.5.x are no longer supported.
+       Further vulnerabilities in the 5.0.x and 5.5.x branches will not be
+       fixed. Users should upgrade to 8.5.x or later to obtain security fixes.
+       Vulnerabilities fixed in Tomcat 5.5.26 onwards have not been assessed to
+       determine if they are present in the 5.0.x branch.</strong></p>
 
     <p>Please note that binary patches are never provided. If you need to
        apply a source code patch, use the building instructions for the
@@ -41,6 +39,8 @@
        <a href="security.html">Tomcat Security Team</a>. Thank you.
     </p>
 
+  </div><h3 id="Table_of_Contents">Table of Contents</h3><div class="text">
+    <ul><li><a href="#Fixed_in_Apache_Tomcat_5.5.36">Fixed in Apache Tomcat 
5.5.36</a></li><li><a href="#Fixed_in_Apache_Tomcat_5.5.35">Fixed in Apache 
Tomcat 5.5.35</a></li><li><a href="#Fixed_in_Apache_Tomcat_5.5.34">Fixed in 
Apache Tomcat 5.5.34</a></li><li><a href="#Fixed_in_Apache_Tomcat_5.5.32">Fixed 
in Apache Tomcat 5.5.32</a></li><li><a 
href="#Fixed_in_Apache_Tomcat_5.5.30">Fixed in Apache Tomcat 
5.5.30</a></li><li><a href="#Fixed_in_Apache_Tomcat_5.5.29">Fixed in Apache 
Tomcat 5.5.29</a></li><li><a href="#Fixed_in_Apache_Tomcat_5.5.28">Fixed in 
Apache Tomcat 5.5.28</a></li><li><a href="#Fixed_in_Apache_Tomcat_5.5.27">Fixed 
in Apache Tomcat 5.5.27</a></li><li><a 
href="#Fixed_in_Apache_Tomcat_5.5.26">Fixed in Apache Tomcat 
5.5.26</a></li><li><a href="#Fixed_in_Apache_Tomcat_5.5.25,_5.0.SVN">Fixed in 
Apache Tomcat 5.5.25, 5.0.SVN</a></li><li><a 
href="#Fixed_in_Apache_Tomcat_5.5.24,_5.0.SVN">Fixed in Apache Tomcat 5.5.24, 
5.0.SVN</a></li><li><a href="#Fixed_in_Apache_Tomcat_5.5
 .23,_5.0.SVN">Fixed in Apache Tomcat 5.5.23, 5.0.SVN</a></li><li><a 
href="#Fixed_in_Apache_Tomcat_5.5.22,_5.0.SVN">Fixed in Apache Tomcat 5.5.22, 
5.0.SVN</a></li><li><a href="#Fixed_in_Apache_Tomcat_5.5.21,_5.0.SVN">Fixed in 
Apache Tomcat 5.5.21, 5.0.SVN</a></li><li><a 
href="#Fixed_in_Apache_Tomcat_5.5.21">Fixed in Apache Tomcat 
5.5.21</a></li><li><a href="#Fixed_in_Apache_Tomcat_5.5.18,_5.0.SVN">Fixed in 
Apache Tomcat 5.5.18, 5.0.SVN</a></li><li><a 
href="#Fixed_in_Apache_Tomcat_5.5.17,_5.0.SVN">Fixed in Apache Tomcat 5.5.17, 
5.0.SVN</a></li><li><a href="#Fixed_in_Apache_Tomcat_5.5.16,_5.0.SVN">Fixed in 
Apache Tomcat 5.5.16, 5.0.SVN</a></li><li><a 
href="#Fixed_in_Apache_Tomcat_5.5.13,_5.0.SVN">Fixed in Apache Tomcat 5.5.13, 
5.0.SVN</a></li><li><a href="#Fixed_in_Apache_Tomcat_5.5.7,_5.0.SVN">Fixed in 
Apache Tomcat 5.5.7, 5.0.SVN</a></li><li><a 
href="#Fixed_in_Apache_Tomcat_5.5.1">Fixed in Apache Tomcat 
5.5.1</a></li><li><a href="#Not_a_vulnerability_in_Tomcat">Not a vulnerability 
in
  Tomcat</a></li></ul>
   </div><h3 id="Fixed_in_Apache_Tomcat_5.5.36"><span 
class="pull-right">released 10 Oct 2012</span> Fixed in Apache Tomcat 
5.5.36</h3><div class="text">
   
     <p><strong>Moderate: DIGEST authentication weakness</strong>

Modified: tomcat/site/trunk/docs/security-6.html
URL: 
http://svn.apache.org/viewvc/tomcat/site/trunk/docs/security-6.html?rev=1897623&r1=1897622&r2=1897623&view=diff
==============================================================================
--- tomcat/site/trunk/docs/security-6.html (original)
+++ tomcat/site/trunk/docs/security-6.html Mon Jan 31 11:14:09 2022
@@ -1,7 +1,5 @@
 <!DOCTYPE html SYSTEM "about:legacy-compat">
-<html lang="en"><head><META http-equiv="Content-Type" content="text/html; 
charset=UTF-8"><meta name="viewport" content="width=device-width, 
initial-scale=1"><link href="res/css/tomcat.css" rel="stylesheet" 
type="text/css"><link href="res/css/fonts/fonts.css" rel="stylesheet" 
type="text/css"><title>Apache Tomcat&reg; - Apache Tomcat 6 
vulnerabilities</title><meta name="author" content="Apache Tomcat 
Project"></head><body><div id="wrapper"><header id="header"><div 
class="clearfix"><div class="menu-toggler pull-left" tabindex="1"><div 
class="hamburger"></div></div><a href="http://tomcat.apache.org/";><img 
class="tomcat-logo pull-left noPrint" alt="Tomcat Home" 
src="res/images/tomcat.png"></a><h1 class="pull-left">Apache 
Tomcat<sup>&reg;</sup></h1><div class="asf-logos pull-right"><a 
href="https://www.apache.org/foundation/contributing.html"; target="_blank" 
class="pull-left"><img 
src="https://www.apache.org/images/SupportApache-small.png"; class="support-asf" 
alt="Support Apache"></a><a h
 ref="http://www.apache.org/"; target="_blank" class="pull-left"><img 
src="res/images/asf_logo.svg" class="asf-logo" alt="The Apache Software 
Foundation"></a></div></div></header><main id="middle"><div><div 
id="mainLeft"><div id="nav-wrapper"><form 
action="https://www.google.com/search"; method="get"><div 
class="searchbox"><input value="tomcat.apache.org" name="sitesearch" 
type="hidden"><input aria-label="Search text" placeholder="Search&hellip;" 
required="required" name="q" id="query" 
type="search"><button>GO</button></div></form><nav><div><h2>Apache 
Tomcat</h2><ul><li><a href="./index.html">Home</a></li><li><a 
href="./taglibs.html">Taglibs</a></li><li><a href="./maven-plugin.html">Maven 
Plugin</a></li></ul></div><div><h2>Download</h2><ul><li><a 
href="./whichversion.html">Which version?</a></li><li><a 
href="https://tomcat.apache.org/download-10.cgi";>Tomcat 10</a></li><li><a 
href="https://tomcat.apache.org/download-90.cgi";>Tomcat 9</a></li><li><a 
href="https://tomcat.apache.org/downloa
 d-80.cgi">Tomcat 8</a></li><li><a 
href="https://tomcat.apache.org/download-migration.cgi";>Tomcat Migration Tool 
for Jakarta EE</a></li><li><a 
href="https://tomcat.apache.org/download-connectors.cgi";>Tomcat 
Connectors</a></li><li><a 
href="https://tomcat.apache.org/download-native.cgi";>Tomcat 
Native</a></li><li><a 
href="https://tomcat.apache.org/download-taglibs.cgi";>Taglibs</a></li><li><a 
href="https://archive.apache.org/dist/tomcat/";>Archives</a></li></ul></div><div><h2>Documentation</h2><ul><li><a
 href="./tomcat-10.1-doc/index.html">Tomcat 10.1 (alpha)</a></li><li><a 
href="./tomcat-10.0-doc/index.html">Tomcat 10.0</a></li><li><a 
href="./tomcat-9.0-doc/index.html">Tomcat 9.0</a></li><li><a 
href="./tomcat-8.5-doc/index.html">Tomcat 8.5</a></li><li><a 
href="./connectors-doc/">Tomcat Connectors</a></li><li><a 
href="./native-doc/">Tomcat Native</a></li><li><a 
href="https://cwiki.apache.org/confluence/display/TOMCAT";>Wiki</a></li><li><a 
href="./migration.html">Migration Guide</a></li><li
 ><a href="./presentations.html">Presentations</a></li><li><a 
 >href="https://cwiki.apache.org/confluence/x/Bi8lBg";>Specifications</a></li></ul></div><div><h2>Problems?</h2><ul><li><a
 > href="./security.html">Security Reports</a></li><li><a 
 >href="./findhelp.html">Find help</a></li><li><a 
 >href="https://cwiki.apache.org/confluence/display/TOMCAT/FAQ";>FAQ</a></li><li><a
 > href="./lists.html">Mailing Lists</a></li><li><a href="./bugreport.html">Bug 
 >Database</a></li><li><a href="./irc.html">IRC</a></li></ul></div><div><h2>Get 
 >Involved</h2><ul><li><a href="./getinvolved.html">Overview</a></li><li><a 
 >href="./source.html">Source code</a></li><li><a 
 >href="./ci.html">Buildbot</a></li><li><a 
 >href="https://cwiki.apache.org/confluence/x/vIPzBQ";>Translations</a></li><li><a
 > href="./tools.html">Tools</a></li></ul></div><div><h2>Media</h2><ul><li><a 
 >href="https://twitter.com/theapachetomcat";>Twitter</a></li><li><a 
 >href="https://www.youtube.com/c/ApacheTomcatOfficial";>YouTube</a></li><li><a 
 >href="https://bl
 ogs.apache.org/tomcat/">Blog</a></li></ul></div><div><h2>Misc</h2><ul><li><a 
href="./whoweare.html">Who We Are</a></li><li><a 
href="https://www.redbubble.com/people/comdev/works/30885254-apache-tomcat";>Swag</a></li><li><a
 href="./heritage.html">Heritage</a></li><li><a 
href="http://www.apache.org";>Apache Home</a></li><li><a 
href="./resources.html">Resources</a></li><li><a 
href="./contact.html">Contact</a></li><li><a 
href="./legal.html">Legal</a></li><li><a 
href="https://www.apache.org/foundation/contributing.html";>Support 
Apache</a></li><li><a 
href="https://www.apache.org/foundation/sponsorship.html";>Sponsorship</a></li><li><a
 href="http://www.apache.org/foundation/thanks.html";>Thanks</a></li><li><a 
href="http://www.apache.org/licenses/";>License</a></li></ul></div></nav></div></div><div
 id="mainRight"><div id="content"><h2 style="display: none;">Content</h2><h3 
id="Table_of_Contents">Table of Contents</h3><div class="text">
-<ul><li><a href="#Apache_Tomcat_6.x_vulnerabilities">Apache Tomcat 6.x 
vulnerabilities</a></li><li><a href="#Fixed_in_Apache_Tomcat_6.0.53">Fixed in 
Apache Tomcat 6.0.53</a></li><li><a href="#Fixed_in_Apache_Tomcat_6.0.50">Fixed 
in Apache Tomcat 6.0.50</a></li><li><a 
href="#Fixed_in_Apache_Tomcat_6.0.48">Fixed in Apache Tomcat 
6.0.48</a></li><li><a href="#Fixed_in_Apache_Tomcat_6.0.47">Fixed in Apache 
Tomcat 6.0.47</a></li><li><a href="#Fixed_in_Apache_Tomcat_6.0.45">Fixed in 
Apache Tomcat 6.0.45</a></li><li><a href="#Fixed_in_Apache_Tomcat_6.0.44">Fixed 
in Apache Tomcat 6.0.44</a></li><li><a 
href="#Fixed_in_Apache_Tomcat_6.0.43">Fixed in Apache Tomcat 
6.0.43</a></li><li><a href="#Fixed_in_Apache_Tomcat_6.0.41">Fixed in Apache 
Tomcat 6.0.41</a></li><li><a href="#Fixed_in_Apache_Tomcat_6.0.39">Fixed in 
Apache Tomcat 6.0.39</a></li><li><a href="#Fixed_in_Apache_Tomcat_6.0.37">Fixed 
in Apache Tomcat 6.0.37</a></li><li><a 
href="#Fixed_in_Apache_Tomcat_6.0.36">Fixed in Apache Tomcat 6.0.
 36</a></li><li><a href="#Fixed_in_Apache_Tomcat_6.0.35">Fixed in Apache Tomcat 
6.0.35</a></li><li><a href="#Fixed_in_Apache_Tomcat_6.0.33">Fixed in Apache 
Tomcat 6.0.33</a></li><li><a href="#Fixed_in_Apache_Tomcat_6.0.32">Fixed in 
Apache Tomcat 6.0.32</a></li><li><a href="#Fixed_in_Apache_Tomcat_6.0.30">Fixed 
in Apache Tomcat 6.0.30</a></li><li><a 
href="#Fixed_in_Apache_Tomcat_6.0.28">Fixed in Apache Tomcat 
6.0.28</a></li><li><a href="#Fixed_in_Apache_Tomcat_6.0.24">Fixed in Apache 
Tomcat 6.0.24</a></li><li><a href="#Fixed_in_Apache_Tomcat_6.0.20">Fixed in 
Apache Tomcat 6.0.20</a></li><li><a href="#Fixed_in_Apache_Tomcat_6.0.18">Fixed 
in Apache Tomcat 6.0.18</a></li><li><a 
href="#Fixed_in_Apache_Tomcat_6.0.16">Fixed in Apache Tomcat 
6.0.16</a></li><li><a href="#Fixed_in_Apache_Tomcat_6.0.14">Fixed in Apache 
Tomcat 6.0.14</a></li><li><a href="#Fixed_in_Apache_Tomcat_6.0.11">Fixed in 
Apache Tomcat 6.0.11</a></li><li><a href="#Fixed_in_Apache_Tomcat_6.0.10">Fixed 
in Apache Tomcat 6.0.1
 0</a></li><li><a href="#Fixed_in_Apache_Tomcat_6.0.9">Fixed in Apache Tomcat 
6.0.9</a></li><li><a href="#Fixed_in_Apache_Tomcat_6.0.6">Fixed in Apache 
Tomcat 6.0.6</a></li><li><a href="#Not_a_vulnerability_in_Tomcat">Not a 
vulnerability in Tomcat</a></li></ul>
-</div><h3 id="Apache_Tomcat_6.x_vulnerabilities">Apache Tomcat 6.x 
vulnerabilities</h3><div class="text">
+<html lang="en"><head><META http-equiv="Content-Type" content="text/html; 
charset=UTF-8"><meta name="viewport" content="width=device-width, 
initial-scale=1"><link href="res/css/tomcat.css" rel="stylesheet" 
type="text/css"><link href="res/css/fonts/fonts.css" rel="stylesheet" 
type="text/css"><title>Apache Tomcat&reg; - Apache Tomcat 6 
vulnerabilities</title><meta name="author" content="Apache Tomcat 
Project"></head><body><div id="wrapper"><header id="header"><div 
class="clearfix"><div class="menu-toggler pull-left" tabindex="1"><div 
class="hamburger"></div></div><a href="http://tomcat.apache.org/";><img 
class="tomcat-logo pull-left noPrint" alt="Tomcat Home" 
src="res/images/tomcat.png"></a><h1 class="pull-left">Apache 
Tomcat<sup>&reg;</sup></h1><div class="asf-logos pull-right"><a 
href="https://www.apache.org/foundation/contributing.html"; target="_blank" 
class="pull-left"><img 
src="https://www.apache.org/images/SupportApache-small.png"; class="support-asf" 
alt="Support Apache"></a><a h
 ref="http://www.apache.org/"; target="_blank" class="pull-left"><img 
src="res/images/asf_logo.svg" class="asf-logo" alt="The Apache Software 
Foundation"></a></div></div></header><main id="middle"><div><div 
id="mainLeft"><div id="nav-wrapper"><form 
action="https://www.google.com/search"; method="get"><div 
class="searchbox"><input value="tomcat.apache.org" name="sitesearch" 
type="hidden"><input aria-label="Search text" placeholder="Search&hellip;" 
required="required" name="q" id="query" 
type="search"><button>GO</button></div></form><nav><div><h2>Apache 
Tomcat</h2><ul><li><a href="./index.html">Home</a></li><li><a 
href="./taglibs.html">Taglibs</a></li><li><a href="./maven-plugin.html">Maven 
Plugin</a></li></ul></div><div><h2>Download</h2><ul><li><a 
href="./whichversion.html">Which version?</a></li><li><a 
href="https://tomcat.apache.org/download-10.cgi";>Tomcat 10</a></li><li><a 
href="https://tomcat.apache.org/download-90.cgi";>Tomcat 9</a></li><li><a 
href="https://tomcat.apache.org/downloa
 d-80.cgi">Tomcat 8</a></li><li><a 
href="https://tomcat.apache.org/download-migration.cgi";>Tomcat Migration Tool 
for Jakarta EE</a></li><li><a 
href="https://tomcat.apache.org/download-connectors.cgi";>Tomcat 
Connectors</a></li><li><a 
href="https://tomcat.apache.org/download-native.cgi";>Tomcat 
Native</a></li><li><a 
href="https://tomcat.apache.org/download-taglibs.cgi";>Taglibs</a></li><li><a 
href="https://archive.apache.org/dist/tomcat/";>Archives</a></li></ul></div><div><h2>Documentation</h2><ul><li><a
 href="./tomcat-10.1-doc/index.html">Tomcat 10.1 (alpha)</a></li><li><a 
href="./tomcat-10.0-doc/index.html">Tomcat 10.0</a></li><li><a 
href="./tomcat-9.0-doc/index.html">Tomcat 9.0</a></li><li><a 
href="./tomcat-8.5-doc/index.html">Tomcat 8.5</a></li><li><a 
href="./connectors-doc/">Tomcat Connectors</a></li><li><a 
href="./native-doc/">Tomcat Native</a></li><li><a 
href="https://cwiki.apache.org/confluence/display/TOMCAT";>Wiki</a></li><li><a 
href="./migration.html">Migration Guide</a></li><li
 ><a href="./presentations.html">Presentations</a></li><li><a 
 >href="https://cwiki.apache.org/confluence/x/Bi8lBg";>Specifications</a></li></ul></div><div><h2>Problems?</h2><ul><li><a
 > href="./security.html">Security Reports</a></li><li><a 
 >href="./findhelp.html">Find help</a></li><li><a 
 >href="https://cwiki.apache.org/confluence/display/TOMCAT/FAQ";>FAQ</a></li><li><a
 > href="./lists.html">Mailing Lists</a></li><li><a href="./bugreport.html">Bug 
 >Database</a></li><li><a href="./irc.html">IRC</a></li></ul></div><div><h2>Get 
 >Involved</h2><ul><li><a href="./getinvolved.html">Overview</a></li><li><a 
 >href="./source.html">Source code</a></li><li><a 
 >href="./ci.html">Buildbot</a></li><li><a 
 >href="https://cwiki.apache.org/confluence/x/vIPzBQ";>Translations</a></li><li><a
 > href="./tools.html">Tools</a></li></ul></div><div><h2>Media</h2><ul><li><a 
 >href="https://twitter.com/theapachetomcat";>Twitter</a></li><li><a 
 >href="https://www.youtube.com/c/ApacheTomcatOfficial";>YouTube</a></li><li><a 
 >href="https://bl
 ogs.apache.org/tomcat/">Blog</a></li></ul></div><div><h2>Misc</h2><ul><li><a 
href="./whoweare.html">Who We Are</a></li><li><a 
href="https://www.redbubble.com/people/comdev/works/30885254-apache-tomcat";>Swag</a></li><li><a
 href="./heritage.html">Heritage</a></li><li><a 
href="http://www.apache.org";>Apache Home</a></li><li><a 
href="./resources.html">Resources</a></li><li><a 
href="./contact.html">Contact</a></li><li><a 
href="./legal.html">Legal</a></li><li><a 
href="https://www.apache.org/foundation/contributing.html";>Support 
Apache</a></li><li><a 
href="https://www.apache.org/foundation/sponsorship.html";>Sponsorship</a></li><li><a
 href="http://www.apache.org/foundation/thanks.html";>Thanks</a></li><li><a 
href="http://www.apache.org/licenses/";>License</a></li></ul></div></nav></div></div><div
 id="mainRight"><div id="content"><h2 style="display: none;">Content</h2><h3 
id="Apache_Tomcat_6.x_vulnerabilities">Apache Tomcat 6.x 
vulnerabilities</h3><div class="text">
     <p>This page lists all security vulnerabilities fixed in released versions
        of Apache Tomcat 6.x. Each vulnerability is given a
        <a href="security-impact.html">security impact rating</a> by the Apache
@@ -14,9 +12,10 @@
        but have either been incorrectly reported against Tomcat or where Tomcat
        provides a workaround are listed at the end of this page.</p>
 
-    <p>Please note that Tomcat 6.0.x is no longer supported. Further
-       vulnerabilities in the 6.0.x branch will not be fixed. Users should
-       upgrade to 7.x or later to obtain security fixes.</p>
+    <p><strong>Please note that Tomcat 6.0.x has reached
+       <a href="tomcat-60-eol.html">end of life</a> and is no longer supported.
+       Further vulnerabilities in the 6.0.x branch will not be fixed. Users
+       should upgrade to 8.5.x or later to obtain security fixes.</strong></p>
 
     <p>Please note that binary patches are never provided. If you need to
        apply a source code patch, use the building instructions for the
@@ -39,6 +38,8 @@
        <a href="security.html">Tomcat Security Team</a>. Thank you.
     </p>
 
+  </div><h3 id="Table_of_Contents">Table of Contents</h3><div class="text">
+    <ul><li><a href="#Fixed_in_Apache_Tomcat_6.0.53">Fixed in Apache Tomcat 
6.0.53</a></li><li><a href="#Fixed_in_Apache_Tomcat_6.0.50">Fixed in Apache 
Tomcat 6.0.50</a></li><li><a href="#Fixed_in_Apache_Tomcat_6.0.48">Fixed in 
Apache Tomcat 6.0.48</a></li><li><a href="#Fixed_in_Apache_Tomcat_6.0.47">Fixed 
in Apache Tomcat 6.0.47</a></li><li><a 
href="#Fixed_in_Apache_Tomcat_6.0.45">Fixed in Apache Tomcat 
6.0.45</a></li><li><a href="#Fixed_in_Apache_Tomcat_6.0.44">Fixed in Apache 
Tomcat 6.0.44</a></li><li><a href="#Fixed_in_Apache_Tomcat_6.0.43">Fixed in 
Apache Tomcat 6.0.43</a></li><li><a href="#Fixed_in_Apache_Tomcat_6.0.41">Fixed 
in Apache Tomcat 6.0.41</a></li><li><a 
href="#Fixed_in_Apache_Tomcat_6.0.39">Fixed in Apache Tomcat 
6.0.39</a></li><li><a href="#Fixed_in_Apache_Tomcat_6.0.37">Fixed in Apache 
Tomcat 6.0.37</a></li><li><a href="#Fixed_in_Apache_Tomcat_6.0.36">Fixed in 
Apache Tomcat 6.0.36</a></li><li><a href="#Fixed_in_Apache_Tomcat_6.0.35">Fixed 
in Apache Tomcat 6.0.35</
 a></li><li><a href="#Fixed_in_Apache_Tomcat_6.0.33">Fixed in Apache Tomcat 
6.0.33</a></li><li><a href="#Fixed_in_Apache_Tomcat_6.0.32">Fixed in Apache 
Tomcat 6.0.32</a></li><li><a href="#Fixed_in_Apache_Tomcat_6.0.30">Fixed in 
Apache Tomcat 6.0.30</a></li><li><a href="#Fixed_in_Apache_Tomcat_6.0.28">Fixed 
in Apache Tomcat 6.0.28</a></li><li><a 
href="#Fixed_in_Apache_Tomcat_6.0.24">Fixed in Apache Tomcat 
6.0.24</a></li><li><a href="#Fixed_in_Apache_Tomcat_6.0.20">Fixed in Apache 
Tomcat 6.0.20</a></li><li><a href="#Fixed_in_Apache_Tomcat_6.0.18">Fixed in 
Apache Tomcat 6.0.18</a></li><li><a href="#Fixed_in_Apache_Tomcat_6.0.16">Fixed 
in Apache Tomcat 6.0.16</a></li><li><a 
href="#Fixed_in_Apache_Tomcat_6.0.14">Fixed in Apache Tomcat 
6.0.14</a></li><li><a href="#Fixed_in_Apache_Tomcat_6.0.11">Fixed in Apache 
Tomcat 6.0.11</a></li><li><a href="#Fixed_in_Apache_Tomcat_6.0.10">Fixed in 
Apache Tomcat 6.0.10</a></li><li><a href="#Fixed_in_Apache_Tomcat_6.0.9">Fixed 
in Apache Tomcat 6.0.9</a><
 /li><li><a href="#Fixed_in_Apache_Tomcat_6.0.6">Fixed in Apache Tomcat 
6.0.6</a></li><li><a href="#Not_a_vulnerability_in_Tomcat">Not a vulnerability 
in Tomcat</a></li></ul>
   </div><h3 id="Fixed_in_Apache_Tomcat_6.0.53"><span class="pull-right">7 
April 2017</span> Fixed in Apache Tomcat 6.0.53</h3><div class="text">
 
   <p><strong>Important: Information Disclosure</strong>



---------------------------------------------------------------------
To unsubscribe, e-mail: dev-unsubscr...@tomcat.apache.org
For additional commands, e-mail: dev-h...@tomcat.apache.org

Reply via email to