Created attachment 218178 [details] Update to 8.5.58, 9.0.38, 10.0.0-M8 Tested on 12.1 amd64: make check-plist/test/install. https://tomcat.apache.org/tomcat-10.0-doc/changelog.html#Tomcat_10.0.0-M8_(markt) https://tomcat.apache.org/tomcat-9.0-doc/changelog.html#Tomcat_9.0.38_(markt) https://tomcat.apache.org/tomcat-8.5-doc/changelog.html#Tomcat_8.5.58_(markt)
Created attachment 218189 [details] Update to 7.0.106 Tested on 12.1-p10 amd64: make check-plist/install. P.S. I'm not the maintainer of the tomcat7.
A commit references this bug: Author: joneum Date: Wed Sep 23 17:22:16 UTC 2020 New revision: 549757 URL: https://svnweb.freebsd.org/changeset/ports/549757 Log: www/tomcat{7,85,9,-devel}: Update to 7.0.106, 8.5.58, 9.0.38, 10.0.0-M8 PR: 249526 Sponsored by: Netzkommune GmbH Changes: head/www/tomcat-devel/Makefile head/www/tomcat-devel/distinfo head/www/tomcat-devel/pkg-plist head/www/tomcat7/Makefile head/www/tomcat7/distinfo head/www/tomcat7/pkg-plist head/www/tomcat85/Makefile head/www/tomcat85/distinfo head/www/tomcat85/pkg-plist head/www/tomcat9/Makefile head/www/tomcat9/distinfo head/www/tomcat9/pkg-plist
This update fixed this CVE-2020-13943 "Apache Tomcat HTTP/2 Request mix-up0": http://tomcat.apache.org/security-10.html http://tomcat.apache.org/security-9.html http://tomcat.apache.org/security-8.html P.S. If somebody from secteam want to add it in security/vuxml/vuln.xml.