Greetings all, another security related question. ...
# lucee
m
Greetings all, another security related question. There are some "high" and "medium" vulnerabilities in the Tomcat version shipped even with the latest Lucee version:
FROM lucee/lucee:5.3.10.120-light-nginx-tomcat9.0-jdk11-openjdk-2303
Snyk has identified that fixes for the following are available:
Copy code
org.apache.tomcat:tomcat-catalina
org.apache.tomcat:tomcat-util
org.apache.tika:tika-core
Would this be a matter of simply overwriting the files that currently exist, using new files (downloaded from...?) during the Docker build? Has anyone else manually attempted to update elements of tomcat server for security in context of Lucee?