Bug 581352 - Are Vulnerabilities Inherited From Tomcat Server to CFT?
Summary: Are Vulnerabilities Inherited From Tomcat Server to CFT?
Status: UNCONFIRMED
Alias: None
Product: CFT
Classification: ECD
Component: General (show other bugs)
Version: unspecified   Edit
Hardware: PC All
: P3 normal
Target Milestone: ---   Edit
Assignee: Project Inbox CLA
QA Contact:
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2023-01-13 14:49 EST by David Christensen CLA
Modified: 2023-01-13 14:49 EST (History)
0 users

See Also:


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description David Christensen CLA 2023-01-13 14:49:03 EST
tomcat-embed JAR’s were found under
configuration/org.eclipse.osgi/1218/0/.cp/lib/tomcat-embed-core-8.0.33.jar
and the plugin using this JAR is org.eclipse.cft.server.core. On the other hand

A question asked to Tomcat support (tomcat-users) was "Being tomcat-embed derived from Tomcat server, could tomcat-embed has the vulnerabilities that Tomcat server has?"
The response was
Yes


I'd like to know if my Eclipse instance, using CFT, would be affected by the vulnerabilities recorded by tomcat.apache.org
https://tomcat.apache.org/security-9.html

Thank you