Skip to content

Conversation

richrace
Copy link
Contributor

Pull Request type

  • Bugfix
  • Feature
  • Refactoring (no functional changes, no api changes)
  • Build related changes
  • WHOSUSING.md
  • Other (please describe):

Changes in this PR

Bump Tomcat version to fix CVE-2025-24813

Alternatives considered

I tried updating Spring Boot to 3.4.5 to use the patched version of Tomcat, but I couldn't get it working. As CVE-2025-24813 is critical, I decided this fix is good enough.

@orkes-harshil orkes-harshil merged commit fce4a76 into conductor-oss:main Jun 3, 2025
2 checks passed
@richrace richrace deleted the fix-CVE-2025-24813 branch June 6, 2025 11:32
shaileshpadave pushed a commit that referenced this pull request Jun 9, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants