Re: Tomcat V8.5.85

2023-02-28 Thread Christopher Schultz
Nitish, On 2/24/23 13:50, Nitish Khune wrote: Since I upgraded from 8.5.84 to 8.5.85 or later, Any REST API with below header throws a context mismatch exception It would be great if you are able to download the 8.5.87 release-candidate and test whether this problem is resolved for you. If

Re: CVE2023-24998 configuration

2023-02-28 Thread A Name
Thanks Mark. I had trouble breaking down where to set the param. My customer may want it lower just for their own internal requirements. On Tue, Feb 28, 2023 at 12:10 PM Mark Thomas wrote: > The default (limit of 10,000 for combined total of query parameters and > upload parts) should be

Re: CVE2023-24998 configuration

2023-02-28 Thread Mark Thomas
The default (limit of 10,000 for combined total of query parameters and upload parts) should be sufficient to mitigate the issue. You can, of course, set the limit lower if you like (maxParameterCount on the Connector(s) in server.xml). Mark On 28/02/2023 16:24, A Name wrote: Just to

CVE2023-24998 configuration

2023-02-28 Thread A Name
Just to confirm - I saw you incorporated fixes for that CVE into recent Tomcats. Is there a setting in Server or Web.xml for these or do they need to be set programmatically within an application using the functions in Commons-FileUpload? Abt

Re: Log rotation issue

2023-02-28 Thread Mark Thomas
On 28/02/2023 03:40, Ragavendhiran Bhiman (rabhiman) wrote: Hi Mark Tomcat version 9.0.54 Operating system? Linux- RedHat Do you mean intermittent rather than intermediate? Yes Intermittent if many errors or too much errors are getting dumped. Usually when the same exception occurs multiple