You are viewing a plain text version of this content. The canonical link for it is here.
Posted to dev@tomcat.apache.org by ma...@apache.org on 2014/02/25 12:27:45 UTC

svn propchange: r1549529 - svn:log

Author: markt
Revision: 1549529
Modified property: svn:log

Modified: svn:log at Tue Feb 25 11:27:45 2014
------------------------------------------------------------------------------
--- svn:log (original)
+++ svn:log Tue Feb 25 11:27:45 2014
@@ -1 +1,2 @@
 Add an option to the Context to control the blocking of XML external entities when parsing XML configuration files and enable this blocking by default when a security manager is used. The block is implemented via a custom resolver to enable the logging of any blocked entities.
+This is the fix for CVE-2013-4590.


---------------------------------------------------------------------
To unsubscribe, e-mail: dev-unsubscribe@tomcat.apache.org
For additional commands, e-mail: dev-help@tomcat.apache.org