You are viewing a plain text version of this content. The canonical link for it is here.
Posted to dev@tomcat.apache.org by ma...@apache.org on 2018/10/31 19:07:15 UTC

svn propchange: r1840603 - svn:log

Author: markt
Revision: 1840603
Modified property: svn:log

Modified: svn:log at Wed Oct 31 19:07:15 2018
------------------------------------------------------------------------------
--- svn:log (original)
+++ svn:log Wed Oct 31 19:07:15 2018
@@ -1 +1,2 @@
 IIS: Improve path parameter handling so that strip_session can remove session IDs that are specified on path parameters in any segment of the URI rather than only the final segment.
+This is part of the fix for CVE-2018-11759


---------------------------------------------------------------------
To unsubscribe, e-mail: dev-unsubscribe@tomcat.apache.org
For additional commands, e-mail: dev-help@tomcat.apache.org