[Freeipa-users] Re: Apache Tomcat Showing on Security Scan as Outdated.

2023-10-31 Thread Marcelo Carvalho via FreeIPA-users
".Tomcat is (should) not be exposed beyond IPA servers so remote users should not be able to make direct requests." Understood. Thank you. Marcelo ___ FreeIPA-users mailing list -- freeipa-users@lists.fedorahosted.org To unsubscribe send an

[Freeipa-users] Re: Apache Tomcat Showing on Security Scan as Outdated.

2023-10-31 Thread Rob Crittenden via FreeIPA-users
Sam Morris via FreeIPA-users wrote: > On Mon, 2023-10-30 at 22:35 +, Marcelo Carvalho via FreeIPA-users > wrote: >> Hi Rob >> >> Thanks for helping out here.  I was pulled sideways and I am >> returning to this issue now.  I am sorry. >> >> Vulnerability showing is "Apache Tomcat 9.0.0-M1 <

[Freeipa-users] Re: Apache Tomcat Showing on Security Scan as Outdated.

2023-10-31 Thread Sam Morris via FreeIPA-users
On Mon, 2023-10-30 at 22:35 +, Marcelo Carvalho via FreeIPA-users wrote: > Hi Rob > > Thanks for helping out here.  I was pulled sideways and I am > returning to this issue now.  I am sorry. > > Vulnerability showing is "Apache Tomcat 9.0.0-M1 < 9.0.68 Request > Smuggling Vulnerability" If

[Freeipa-users] Re: Apache Tomcat Showing on Security Scan as Outdated.

2023-10-30 Thread Marcelo Carvalho via FreeIPA-users
Hi Rob Thanks for helping out here. I was pulled sideways and I am returning to this issue now. I am sorry. Vulnerability showing is "Apache Tomcat 9.0.0-M1 < 9.0.68 Request Smuggling Vulnerability" Is there a way and a need to update Apache Tomcat from within FreeIPA? If so, is this

[Freeipa-users] Re: Apache Tomcat Showing on Security Scan as Outdated.

2023-10-23 Thread Rob Crittenden via FreeIPA-users
Marcelo Carvalho via FreeIPA-users wrote: > Hi everyone. > > We are running FreeIPA version: > > VERSION: 4.10.1, API_VERSION: 2.251 > > Tomcat showing running is: > > [root@corp-freeipa-01 tomcat]# java -cp catalina.jar > org.apache.catalina.util.ServerInfo > Server version: Apache