Re: JumpStart is up

2022-07-12 Thread Thiago H. de Paula Figueiredo
Great news! Thanks so much, Geoff! JumpStart is an invaluable resource for Tapestry users. On Sun, Jul 10, 2022 at 9:00 PM JumpStart wrote: > > JumpStart is up! Its new home is https://tapestry-jumpstart.org/jumpstart > . Yesterday it had the wrong > ce

[CVE-2022-31781] Apache Tapestry denial of service vulnerability

2022-07-12 Thread Thiago H. de Paula Figueiredo
Regular Expression Denial of Service (ReDoS) in ContentType.java. (GHSL-2022-022) (CVE-2022-31781) PRODUCT AFFECTED: This issue affects Apache Tapestry 5.8.1. PROBLEM: Severity: low Apache Tapestry up to version 5.8.1 is vulnerable to Regular Expression Denial of Service (ReDoS) in the way it