You are viewing a plain text version of this content. The canonical link for it is here.
Posted to dev@tomcat.apache.org by ma...@apache.org on 2016/02/22 13:17:33 UTC

svn propchange: r1727034 - svn:log

Author: markt
Revision: 1727034
Modified property: svn:log

Modified: svn:log at Mon Feb 22 12:17:33 2016
------------------------------------------------------------------------------
--- svn:log (original)
+++ svn:log Mon Feb 22 12:17:33 2016
@@ -1,2 +1,3 @@
 When using the new sessionAttributeValueClassNameFilter, apply the filter earlier rather than loading the class and then deciding to filter it out.
 When a SecurityManager is used, enable filtering by default.
+This is part 1 of 2 of the fix for CVE-2016-0714


---------------------------------------------------------------------
To unsubscribe, e-mail: dev-unsubscribe@tomcat.apache.org
For additional commands, e-mail: dev-help@tomcat.apache.org