Apache Tomcat Version 4.0 Beta 2 ================================= Release Notes ============= $Id$ ============ INTRODUCTION: ============ This document describes the changes that have been made in the current beta release of Apache Tomcat, relative to the previous release. Bug reports should be entered at the interim bug reporting system for Jakarta projects at: http://nagoya.apache.org/bugzilla/ Please use project codes "Catalina" and "Jasper" for servlet-related and JSP-related bug reports, respectively. ------------------------ Important Security Notes: ------------------------ This release includes fixes for two security vulnerabilities that have been reported against Tomcat 4.0 beta 1: * A "cross site scripting" vulnerability would cause the enclosed JavaScript code to be executed (on the client) with a URL like: http://localhost:8080/