diff --git a/etc/tomcat/conf/catalina.properties b/etc/tomcat/conf/catalina.properties index 419a61b..9cc5a75 100644 --- a/etc/tomcat/conf/catalina.properties +++ b/etc/tomcat/conf/catalina.properties @@ -109,10 +109,12 @@ shared.loader= tomcat.util.scan.StandardJarScanFilter.jarsToSkip=\ annotations-api.jar,\ ant-junit*.jar,\ -ant-launcher.jar,\ -ant.jar,\ +ant-launcher*.jar,\ +ant*.jar,\ asm-*.jar,\ aspectj*.jar,\ +bcel*.jar,\ +biz.aQute.bnd*.jar,\ bootstrap.jar,\ catalina-ant.jar,\ catalina-ha.jar,\ @@ -125,6 +127,7 @@ cobertura-*.jar,\ commons-beanutils*.jar,\ commons-codec*.jar,\ commons-collections*.jar,\ +commons-compress*.jar,\ commons-daemon.jar,\ commons-dbcp*.jar,\ commons-digester*.jar,\ @@ -166,6 +169,8 @@ log4j*.jar,\ mail*.jar,\ objenesis-*.jar,\ oraclepki.jar,\ +org.hamcrest.core_*.jar,\ +org.junit_*.jar,\ oro-*.jar,\ servlet-api-*.jar,\ servlet-api.jar,\ @@ -184,6 +189,7 @@ tomcat-util-scan.jar,\ tomcat-util.jar,\ tomcat-websocket.jar,\ tools.jar,\ +unboundid-ldapsdk-*.jar,\ websocket-api.jar,\ wsdl4j*.jar,\ xercesImpl.jar,\ @@ -208,3 +214,7 @@ tomcat.util.buf.StringCache.byte.enabled=true #tomcat.util.buf.StringCache.char.enabled=true #tomcat.util.buf.StringCache.trainThreshold=500000 #tomcat.util.buf.StringCache.cacheSize=5000 + +# Disable use of some privilege blocks Tomcat doesn't need since calls to the +# code in question are always already inside a privilege block +org.apache.el.GET_CLASSLOADER_USE_PRIVILEGED=false diff --git a/gradle.properties b/gradle.properties index 5455db4..2c251d5 100644 --- a/gradle.properties +++ b/gradle.properties @@ -2,7 +2,7 @@ appName=karuta psiProbeVersion=3.7.2 -tomcatVersion=9.0.70 +tomcatVersion=9.0.73 waroverlayPluginVersion=0.9.3