qunarcorp / bistoury

Bistoury是去哪儿网的java应用生产问题诊断工具,提供了一站式的问题诊断方案
GNU General Public License v3.0
4k stars 824 forks source link

There is a vulnerability in Apache Tomcat 8.5.5,upgrade recommended #129

Open QiAnXinCodeSafe opened 2 years ago

QiAnXinCodeSafe commented 2 years ago

https://github.com/qunarcorp/bistoury/blob/b83b87032c3a394df31300a4fe3a1123cf6d7917/pom.xml#L91

CVE-2020-1938 CVE-2017-5651 CVE-2018-8014 CVE-2017-5648 CVE-2016-8735

Recommended upgrade version:8.5.68