Hi all,
NVD - CVE-2025-24813 was published last week, describing an unauthenticated remote code vulnerability in Tomcat, exaccerbated by running as root.
I see it’s mitigated in Tomcat v9.0.99, and it looks like the Xwiki Docker container is currently running under v9.0.98.0; are there plans to bump that Tomcat version? Separately, are there plans to change the image to run under a non-root user?
3 posts - 3 participants