You are viewing a plain text version of this content. The canonical link for it is here.
Posted to dev@tomcat.apache.org by ma...@apache.org on 2016/10/27 12:26:42 UTC

svn propchange: r1754728 - svn:log

Author: markt
Revision: 1754728
Modified property: svn:log

Modified: svn:log at Thu Oct 27 12:26:42 2016
------------------------------------------------------------------------------
--- svn:log (original)
+++ svn:log Thu Oct 27 12:26:42 2016
@@ -1 +1,2 @@
 Provide a mechanism that enables the container to check if a component (typically a web application) has been granted a given permission when running under a SecurityManager without the current execution stack having to have passed through the component. Use this new mechanism to extend SecurityManager protection to the system property replacement feature of the digester.
+This is the fix for CVE-2016-6794


---------------------------------------------------------------------
To unsubscribe, e-mail: dev-unsubscribe@tomcat.apache.org
For additional commands, e-mail: dev-help@tomcat.apache.org