tomcat-users mailing list archives

Site index · List index
Message view « Date » · « Thread »
Top « Date » · « Thread »
From Jamie Jackson <jamieja...@gmail.com>
Subject Re: maxFileSize
Date Thu, 01 Oct 2015 20:47:20 GMT
Point taken, Christopher. I did just discover that I'm actually running
7.0.59, which isn't as egregious as 7.0.20. (I had got the version
information from an unreliable source before, apparently.)

On Thu, Oct 1, 2015 at 3:41 PM, Christopher Schultz <
chris@christopherschultz.net> wrote:

> -----BEGIN PGP SIGNED MESSAGE-----
> Hash: SHA256
>
> Jamie,
>
> On 10/1/15 1:29 PM, Jamie Jackson wrote:
> > I'd meant to include that I'm running Tomcat 7.0.20 on Oracle Java
> > 7 (64-bit).
>
> Before you do anything else, you really need to upgrade Tomcat. That
> version of Tomcat is more than 4 years old and has publicly-disclosed,
> un-patched vulnerabilities.
>
> http://tomcat.apache.org/security-7.html
> http://tomcat.apache.org/tomcat-7.0-doc/changelog.html
>
> If you have the choice, upgrade to Tomcat 8.0.27 which will be
> available in a few hours.
>
> - -chris
>
> > On Thu, Oct 1, 2015 at 1:22 PM, Jamie Jackson
> > <jamiejaxon@gmail.com> wrote:
> >
> >> Hi Folks,
> >>
> >> My question has a few facets:
> >>
> >>
> >> 1. How do you get the active maxFileSize value from Tomcat? (Is
> >> it possible in, say, jConsole?) 2. Is the default value's ("-1"
> >> <https://tomcat.apache.org/tomcat-7.0-doc/servletapi/javax/servlet/an
> notation/MultipartConfig.html#maxFileSize()>)
> >> meaning documented anywhere? My guess is that it means
> >> "unlimited," but that's just a guess. (If it's not documented, I
> >> think it should be.) 3. How do people know how to translate these
> >> API items to XML (in web.xml)? I know I can find the answer for
> >> maxFileSize on StackOverflow, but it seems like there should be
> >> general guidance on how to make that leap (if there isn't
> >> specific guidance for those configurations in the official
> >> documentation).
> >>
> >> Thanks, Jamie
> >>
> >
> -----BEGIN PGP SIGNATURE-----
> Comment: GPGTools - http://gpgtools.org
>
> iQIcBAEBCAAGBQJWDYxcAAoJEBzwKT+lPKRY9LIP/RUPT67REVZIUPT4SLZoXykd
> k0UpFj7FMHiu6HJNlJDx/h5Wv+WFdcsHLMTZl2ut+o2l4c+DDfl5v4J0KxRuYnq6
> pht9xnVF/3BTk8u7jeUFrwBHebPZUknmsl2FNxh2Hdc3D+hLYOyUOJlG5cWrGXRu
> utZdtArbTOZEmUvSituKx1kp3+D/QhzBaNK68dFg+xnK4yfu6LxjiTfCLT5lzKUp
> iBV9Y9ytGRBXEPzMRGzZPbf4GY6IUBmQB6cC8h6AjQaeZlb9wloxMve2sS18TXuD
> xTFwxQuljUWPGPXdn0CYI4pqY47u8qA8fEbwdDjaHXlf1xW3jZKy8XboSYmtNxC3
> 6y9d4GimBcXYLmOHgqkV0rdoj8CFqlDtDf4AfD8k4BgKJ1YPi9QFRen8xSBZRmnM
> ps7oGiVu7SEprFmFcEl/t9Dy4mNgZoF0WTrAX5XhPzQiZKsXF5B6EdhT2gFUS5Qr
> c7vPsP18BoP8GfT3rImkN5uTY8z1LLaY8EJk41BYwRrcOilCOPyv4U5zfiCj6GWg
> 8ZjkZr+z9PcgY9J9s2BpkQjQT6r+QUgnDJXsLjmL/O25gxZO8vg0Sq1mi06nFpup
> hFf5c73/3PGMLwkSovX/eOk/mA91fadiSaiC4lH/nuUkMhMwoTFojNq8cy3E3W9j
> krfw/WrmOblbE6ZkEDrt
> =iOXv
> -----END PGP SIGNATURE-----
>
> ---------------------------------------------------------------------
> To unsubscribe, e-mail: users-unsubscribe@tomcat.apache.org
> For additional commands, e-mail: users-help@tomcat.apache.org
>
>

Mime
  • Unnamed multipart/alternative (inline, None, 0 bytes)
View raw message