Some Eclipse Foundation services are deprecated, or will be soon. Please ensure you've read this important communication.

Bug 357493

Summary: Dependency on Tomcat 7.0.21
Product: [RT] Gemini.Web Reporter: Violeta Georgieva <milesg78>
Component: unknownAssignee: Project Inbox <gemini.web-inbox>
Status: CLOSED FIXED QA Contact:
Severity: normal    
Priority: P3 CC: wayne.beaton
Version: unspecified   
Target Milestone: ---   
Hardware: All   
OS: All   
Whiteboard:

Description Violeta Georgieva CLA 2011-09-13 10:00:38 EDT
See https://dev.eclipse.org/ipzilla/show_bug.cgi?id=5539
Comment 1 Wayne Beaton CLA 2011-09-13 11:15:50 EDT
The CQ indicates that it was opened due to "security vulnerabilities in Tomcat 7.0.12". Are any Gemini Web consumers subject to those security vulnerabilities? I assume yes, since the 2.0 includes the problematic 7.0.12.

At a minimum, this bug's title should be changed to reflect the nature of the vulnerability, comments added to describe the problem, and the 'security' keyword added.