Re: MDB Activation Properties

2024-07-09 Thread Richard Zowalla
Hey Alex, Would be great to get a doc update PR ;-) Thanks Richard > Am 09.07.2024 um 11:02 schrieb Alex The Rocker : > > What a "funny" coincidence! > > Today I was investigating ways of setting up JMS parameters in TomEE, > and I too found quite outdated (if not in contradiction) pages. > >

Re: CVE-2024-34750

2024-07-09 Thread Richard Zowalla
To clarify a bit more: Feel free to provide a PR backporting the required changes (may also be relevant for bouncycastle). We have recently updated our download page and now explicitly state: "SECURITY NOTICE: This software is developed and maintained by unpaid volunteers who donate time as

Re: MDB Activation Properties

2024-07-09 Thread Alex The Rocker
What a "funny" coincidence! Today I was investigating ways of setting up JMS parameters in TomEE, and I too found quite outdated (if not in contradiction) pages. This say understatement: "there's plenty of improvement opportunity in TomEE JMS-related documentation"... I'll see if I can recap all

Re: MDB Activation Properties

2024-07-09 Thread Richard Zowalla
Hi, at a first glance, it looks like the docs are just out-dated. I would check the docs of the latest activemq (classic) version used in TomEE 8 and compare, if these properties are still available or have changed: https://activemq.apache.org/components/classic/documentation/redelivery-policy

Re: CVE-2024-34750

2024-07-09 Thread Richard Zowalla
Hello, most likely yes (haven't checked in detail). Personally, I'm not going to port anything back to TomEE 9.x as I'm currently focused on 10.x work. However, I am available to review any community driven patches/initiatives via PRs targeting tomee-9.x branch. Best regards Richard On 2024/0

CVE-2024-34750

2024-07-09 Thread COURTAULT Francois
THALES GROUP LIMITED DISTRIBUTION to email recipients Hello everyone, TomEE 9.1.3 is based on Tomcat 10.0.27. So the question is: Is TomEE 9.1.3 vulnerable to this CVE ? If the answer is yes, will you provide a fix for Tomcat 10.0.27 which is not maintained anymore ? and so will you release a ne