ea-tomcat101 (10.1.57-1+3.1.cpanel) stable; urgency=low

  * EA-13495: Update ea-tomcat101 from v10.1.56 to v10.1.57

 -- EA4 Update Bot <cory.mcintire@webpros.com>  Thu, 09 Jul 2026 00:00:00 -0000

ea-tomcat101 (10.1.56-1) stable; urgency=low

  * EA-13475: Update ea-tomcat101 from v10.1.55 to v10.1.56
  * (CVE-2026-55956) Moderate: Security constraints for default servlet ignored method
  * (CVE-2026-55955) Low: EncryptInterceptor not protected against replay attacks
  * (CVE-2026-55276) Low: Logged effective web.xml is incomplete
  * (CVE-2026-53434) Low: Invalid CRL configuration doesn't trigger failure for FFM Connector
  * (CVE-2026-53404) Low: Bad ornext processing in RewriteValve
  * (CVE-2026-50229) Low: XSS in number guess example

 -- EA4 Update Bot <cory.mcintire@webpros.com>  Thu, 25 Jun 2026 00:00:00 -0000

ea-tomcat101 (10.1.55-1) stable; urgency=low

  * EA-13434: Update ea-tomcat101 from v10.1.54 to v10.1.55
  * (CVE-2026-43515) Moderate: Security constraints not correctly applied
  * (CVE-2026-43512) Moderate: Digest authenticator will authenticate any unknown user
  * (CVE-2026-43514) Low: AJP secret compared in non-constant time
  * (CVE-2026-43513) Low: LockOutRealm treats user names as case-sensitive
  * (CVE-2026-42498) Low: WebSocket authentication header exposure
  * (CVE-2026-41293) Low: HTTP/2 request headers not validated
  * (CVE-2026-41284) Low: Unbounded read in WebDAV LOCK and PROPFIND handling

 -- EA4 Update Bot <cory.mcintire@webpros.com>  Wed, 13 May 2026 00:00:00 -0000

ea-tomcat101 (10.1.54-1) stable; urgency=low

  * EA-13399: Update ea-tomcat101 from v10.1.53 to v10.1.54
  * (CVE-2026-34486) Important: The fix for CVE-2026-29146 allowed the bypass of the EncryptInterceptor
  * (CVE-2026-34500) Moderate: OCSP checks sometimes soft-fail with FFM even when soft-fail is disabled
  * (CVE-2026-34487) Low: Cloud membership for clustering component exposed the Kubernetes bearer token
  * (CVE-2026-34483) Low: Incomplete escaping of JSON access logs

 -- EA4 Update Bot <cory.mcintire@webpros.com>  Sat, 04 Apr 2026 00:00:00 -0000

ea-tomcat101 (10.1.53-1) stable; urgency=low

  * EA-13379: Update ea-tomcat101 from v10.1.52 to v10.1.53

 -- Cory McIntire <cory.mcintire@webpros.com>  Tue, 24 Mar 2026 00:00:00 -0000

ea-tomcat101 (10.1.52-2) stable; urgency=low

  * EA4-248: Update changelog with CVE data.

 -- Cory McIntire <cory.mcintire@webpros.com>  Tue, 24 Feb 2026 00:00:00 -0000

ea-tomcat101 (10.1.52-1) stable; urgency=low

  * EA-13328: Update ea-tomcat101 from v10.1.50 to v10.1.52
  * Moderate: Incomplete OCSP verification checks CVE-2026-24734

 -- Cory McIntire <cory.mcintire@webpros.com>  Wed, 28 Jan 2026 00:00:00 -0000

ea-tomcat101 (10.1.50-1) stable; urgency=low

  * EA-13285: Update ea-tomcat101 from v10.1.49 to v10.1.50
  * Low: Security constraint bypass CVE-2026-24733
  * Moderate: Client certificate verification bypass due to virtual host mapping CVE-2025-66614

 -- Cory McIntire <cory.mcintire@webpros.com>  Tue, 09 Dec 2025 00:00:00 -0000

ea-tomcat101 (10.1.49-1) stable; urgency=low

  * EA-13257: Update ea-tomcat101 from v10.1.48 to v10.1.49

 -- Cory McIntire <cory.mcintire@webpros.com>  Wed, 12 Nov 2025 00:00:00 -0000

ea-tomcat101 (10.1.48-1) stable; urgency=low

  * EA-13223: Update ea-tomcat101 from v10.1.47 to v10.1.48

 -- Cory McIntire <cory.mcintire@webpros.com>  Tue, 21 Oct 2025 00:00:00 -0000

ea-tomcat101 (10.1.47-1) stable; urgency=low

  * EA-13187: Update ea-tomcat101 from v10.1.46 to v10.1.47
  * Low: Delayed cleaning of multipart upload temporary files may lead to DoS CVE-2025-61795

 -- Cory McIntire <cory.mcintire@webpros.com>  Thu, 09 Oct 2025 00:00:00 -0000

ea-tomcat101 (10.1.46-1) stable; urgency=low

  * EA-13164: Update ea-tomcat101 from v10.1.45 to v10.1.46

 -- Cory McIntire <cory.mcintire@webpros.com>  Mon, 06 Oct 2025 00:00:00 -0000

ea-tomcat101 (10.1.45-1) stable; urgency=low

  * EA-13090: Update ea-tomcat101 from v10.1.44 to v10.1.45
  * Low: Console manipulation via escape sequences in log messages CVE-2025-55754
  * Important: Directory traversal via Rewrite Valve with possible remote code execution if PUT is enabled CVE-2025-55752

 -- Cory McIntire <cory.mcintire@webpros.com>  Mon, 08 Sep 2025 00:00:00 -0000

ea-tomcat101 (10.1.44-1) stable; urgency=low

  * EA-13066: Update ea-tomcat101 from v10.1.43 to v10.1.44
  * Important: DoS in HTTP/2 due to client triggered stream reset CVE-2025-48989

 -- Cory McIntire <cory.mcintire@webpros.com>  Thu, 07 Aug 2025 00:00:00 -0000

ea-tomcat101 (10.1.43-1) stable; urgency=low

  * EA-13004: Update ea-tomcat101 from v10.1.42 to v10.1.43
  * Low: DoS due to overflow in file upload limit CVE-2025-52520
  * Important: DoS via excessive HTTP/2 streams CVE-2025-53506

 -- Cory McIntire <cory.mcintire@webpros.com>  Tue, 08 Jul 2025 00:00:00 -0000

ea-tomcat101 (10.1.42-1) stable; urgency=low

  * EA-12927: Update ea-tomcat101 from v10.1.41 to v10.1.42
  * [CVE-2025-48976] Allocation of resources for multipart headers with insufficient limits enabled a DoS vulnerability in Apache Commons FileUpload
  * [CVE-2025-48988] Allocation of Resources Without Limits or Throttling vulnerability in Apache Tomcat
  * [CVE-2025-49125] Authentication Bypass Using an Alternate Path or Channel vulnerability in Apache Tomcat
  * [CVE-2025-49124] Untrusted Search Path vulnerability in Apache Tomcat installer for Windows. During installation, the Tomcat installer for Windows used icacls.exe without specifying a full path.

 -- Cory McIntire <cory.mcintire@webpros.com>  Tue, 10 Jun 2025 00:00:00 -0000

ea-tomcat101 (10.1.41-1) stable; urgency=low

  * EA-12865: Update ea-tomcat101 from v10.1.40 to v10.1.41

 -- Cory McIntire <cory.mcintire@webpros.com>  Tue, 13 May 2025 00:00:00 -0000

ea-tomcat101 (10.1.40-1) stable; urgency=low

  * EA-12806: Update ea-tomcat101 from v10.1.39 to v10.1.40
  * Important: Denial of Service via invalid HTTP priority header CVE-2025-31650
  * Low: Rewrite rule bypass CVE-2025-31651

 -- Cory McIntire <cory.mcintire@webpros.com>  Wed, 09 Apr 2025 00:00:00 -0000

ea-tomcat101 (10.1.39-1) stable; urgency=low

  * EA-12756: Update ea-tomcat101 from v10.1.36 to v10.1.39
  * Improve the checks for exposure to and protection against CVE-2024-56337 so that reflection is not used unless required.
  * Remote Code Execution and/or Information disclosure and/or malicious content added to uploaded files via write enabled Default Servlet - CVE-2025-24813

 -- Cory McIntire <cory.mcintire@webpros.com>  Mon, 10 Mar 2025 00:00:00 -0000

ea-tomcat101 (10.1.36-1) stable; urgency=low

  * EA-12722: Update ea-tomcat101 from v10.1.35 to v10.1.36

 -- Cory McIntire <cory.mcintire@webpros.com>  Wed, 19 Feb 2025 00:00:00 -0000

ea-tomcat101 (10.1.35-1) stable; urgency=low

  * EA-12693: Update ea-tomcat101 from v10.1.34 to v10.1.35
  * Add a check to ensure that, if one or more web applications are potentially vulnerable to CVE-2024-56337, the JVM has been configured to protect against the vulnerability and to configure the JVM correctly if not. Where one or more web applications are potentially vulnerable to CVE-2004-56337 and the JVM cannot be correctly configured or it cannot be confirmed that the JVM has been correctly configured, prevent the impacted web applications from starting.

 -- Cory McIntire <cory.mcintire@webpros.com>  Mon, 10 Feb 2025 00:00:00 -0000

ea-tomcat101 (10.1.34-1) stable; urgency=low

  * EA-12606: Update ea-tomcat101 from v10.1.33 to v10.1.34
  * CVE-2024-54677: Apache Tomcat: DoS in examples web application
  * CVE-2024-50379: Apache Tomcat: RCE due to TOCTOU issue in JSP compilation

 -- Cory McIntire <cory@cpanel.net>  Tue, 10 Dec 2024 00:00:00 -0000

ea-tomcat101 (10.1.33-1) stable; urgency=low

  * EA-12555: Update ea-tomcat101 from v10.1.30 to v10.1.33
  * CVE-2024-52316: Apache Tomcat: Authentication bypass when using Jakarta Authentication API
  * CVE-2024-52317: Apache Tomcat: Request/response mix-up with HTTP/2
  * CVE-2024-52318: Apache Tomcat: Incorrect JSP tag recycling leads to XSS

 -- Cory McIntire <cory@cpanel.net>  Mon, 18 Nov 2024 00:00:00 -0000

ea-tomcat101 (10.1.30-1) stable; urgency=low

  * EA-12394: Update ea-tomcat101 from v10.1.28 to v10.1.30

 -- Cory McIntire <cory@cpanel.net>  Tue, 17 Sep 2024 00:00:00 -0000

ea-tomcat101 (10.1.28-1) stable; urgency=low

  * EA-12325: Update ea-tomcat101 from v10.1.26 to v10.1.28

 -- Cory McIntire <cory@cpanel.net>  Tue, 06 Aug 2024 00:00:00 -0000

ea-tomcat101 (10.1.26-1) stable; urgency=low

  * EA-12290: Update ea-tomcat101 from v10.1.24 to v10.1.26

 -- Cory McIntire <cory@cpanel.net>  Thu, 18 Jul 2024 00:00:00 -0000

ea-tomcat101 (10.1.24-1) stable; urgency=low

  * EA-12147: Update ea-tomcat101 from v10.1.20 to v10.1.24

 -- Cory McIntire <cory@cpanel.net>  Mon, 13 May 2024 00:00:00 -0000

ea-tomcat101 (10.1.20-1) stable; urgency=low

  * EA-12081: Update ea-tomcat101 from v10.1.10 to v10.1.20

 -- Cory McIntire <cory@cpanel.net>  Wed, 10 Apr 2024 00:00:00 -0000

ea-tomcat101 (10.1.10-2) stable; urgency=low

  * ZC-11732: Add SSL and Port information. Clarify role in support and docs

 -- Dan Muey <dan@cpanel.net>  Thu, 28 Mar 2024 00:00:00 -0000

ea-tomcat101 (10.1.10-1) stable; urgency=low

  * ZC-11053: Initial Build

 -- Julian Brown <julian.brown@cpanel.net>  Mon, 31 Jul 2023 00:00:00 -0000

