Re: [EXTERNAL] Re: Why tomcat "Incorrect URL decoding in RewriteValve may allow security control bypass" is rated 'Low' on tomcat page but 'Critical' on NIST ?
Peter Kreuser <[email protected]> Tue, 21 Jul 2026 20:49:28 +0200
| Newsgroups | gmane.comp.jakarta.tomcat.user |
|---|---|
| Message-ID | <[email protected]> |
Guiseppe, Throwing in my 2cts. I assume noone here could improve the situation. The rating is already low. S= o unless your company weighs the rating of the app higher than the NIST rati= ng, this cannot be solved. I don't know who is forcing you to update - in my company we could always ge= t approval of a risk acceptance with a comprehensible explanation. On a different note, I don't see a reason why you should not be able to upda= te a minor version. You would have to update anyways if the CVSS would be a "real" 9.1... Peter > Am 21.07.2026 um 20:12 schrieb Sebastian Trost via users <[email protected]= che.org>: >=20 > =EF=BB=BFGiuseppe, >=20 >> On 7/21/26 18:51, LAURIA Giuseppe via users wrote: >> And I assume that this will not get any better in the future, but that su= ch cases are still often discovered which do not concern us. >> Couldn=E2=80=99t there be something better from the Tomcat corner? > Since this is an open source project I'm sure that suggestions are always w= elcome. >=20 > Sebastian >=20 > --------------------------------------------------------------------- > To unsubscribe, e-mail: [email protected] > For additional commands, e-mail: [email protected]