Internals of setMaxInactiveInterval

2021-07-12 Thread Saurav Sarkar
Hi All, I would like to understand the internals of Session~setMaxInactiveInterval in tomcat. I understand that if HTTP requests are not received within the said interval then the session is cleared. All the objects belonging to the session will be gone. Does that also mean that the existing

RE: [SECURITY] CVE-2021-30639 Apache Tomcat DoS

2021-07-12 Thread jonmcalexander
Corrected Numbers. Subtract 3667 desktops from the 8.5.64 numbers. 8.5.64 DISCOVERED_VERSION (Multiple Items) ASSET_CLAS_DS DESKTOP Row Labels Count of CI_NM_HOST (blank) 3667 Grand Total 3667 Distributed Servers: DISCOVERED_VERSION (Multiple Items) ASSET_CLAS_DS DISTRIBUTED

Re: When does tomcat 7.0.76 determine it needs to redeploy the war file?

2021-07-12 Thread Mark Thomas
On 12/07/2021 19:21, Brian Wolfe wrote: Hi, As the subject asks, when does tomcat decide that it needs to redeploy the war file? I know the usual one where the app folder does not exist. Basically I have an app where some changes were made to the webapp folder, but were not made in the

When does tomcat 7.0.76 determine it needs to redeploy the war file?

2021-07-12 Thread Brian Wolfe
Hi, As the subject asks, when does tomcat decide that it needs to redeploy the war file? I know the usual one where the app folder does not exist. Basically I have an app where some changes were made to the webapp folder, but were not made in the accompanied war file. Then we updated the web.xml

Re: IIS 10.0 as Tomcat reverse proxy does not send auth_type and remote_user AJP heder

2021-07-12 Thread Mark Thomas
On 12/07/2021 07:21, Paolo Clerici wrote: Hi Mark, 1) Start the Internet Information Services (IIS) Manager. 2) Locate and select site "test" in the IIS tree. 3) Double-click the Authentication icon. 4) Select Windows Authentication. 5) Click Enable in the Actions menu. 6) Restart IIS When I

[SECURITY] CVE-2021-33037 Apache Tomcat HTTP request smuggling

2021-07-12 Thread Mark Thomas
CVE-2021-33037 HTTP request smuggling Severity: Important Vendor: The Apache Software Foundation Versions Affected: Apache Tomcat 10.0.0-M1 to 10.0.6 Apache Tomcat 9.0.0.M1 to 9.0.46 Apache Tomcat 8.5.0 to 8.5.66 Description: Apache Tomcat did not correctly parse the HTTP transfer-encoding

[SECURITY] CVE-2021-30640 Apache Tomcat JNDI realm authentication weakness

2021-07-12 Thread Mark Thomas
CVE-2021-30640 JNDI Realm Authentication Weakness Severity: Low Vendor: The Apache Software Foundation Versions Affected: Apache Tomcat 10.0.0-M1 to 10.0.5 Apache Tomcat 9.0.0.M1 to 9.0.45 Apache Tomcat 8.5.0 to 8.5.65 Apache Tomcat 7.0.0 to 7.0.108 Description: Queries made by the JNDI Realm

[SECURITY] CVE-2021-30639 Apache Tomcat DoS

2021-07-12 Thread Mark Thomas
CVE-2021-30639 Denial of Service Severity: Important Vendor: The Apache Software Foundation Versions Affected: Apache Tomcat 10.0.3 to 10.0.4 Apache Tomcat 9.0.44 Apache Tomcat 8.5.64 Description: An error introduced as part of a change to improve error handling during non-blocking I/O meant

Re: IIS 10.0 as Tomcat reverse proxy does not send auth_type and remote_user AJP heder

2021-07-12 Thread Paolo Clerici
Hi Mark, 1) Start the Internet Information Services (IIS) Manager. 2) Locate and select site "test" in the IIS tree. 3) Double-click the Authentication icon. 4) Select Windows Authentication. 5) Click Enable in the Actions menu. 6) Restart IIS When I request the resource