blob: b578737f1346496b68aeab6a39e87fee489efac1 [file] [log] [blame]
<!DOCTYPE html>
<html lang="en">
<head>
<meta charset="UTF-8">
<meta http-equiv="X-UA-Compatible" content="IE=edge">
<meta name="viewport" content="width=device-width, initial-scale=1">
<title>Apache TomEE</title>
<meta name="description"
content="Apache TomEE is a lightweight, yet powerful, JavaEE Application server with feature rich tooling." />
<meta name="keywords" content="tomee,asf,apache,javaee,jee,shade,embedded,test,junit,applicationcomposer,maven,arquillian" />
<meta name="author" content="Luka Cvetinovic for Codrops" />
<link rel="icon" href="../favicon.ico">
<link rel="icon" type="image/png" href="../favicon.png">
<meta name="msapplication-TileColor" content="#80287a">
<meta name="theme-color" content="#80287a">
<link rel="stylesheet" type="text/css" href="../css/normalize.css">
<link rel="stylesheet" type="text/css" href="../css/bootstrap.css">
<link rel="stylesheet" type="text/css" href="../css/owl.css">
<link rel="stylesheet" type="text/css" href="../css/animate.css">
<link rel="stylesheet" type="text/css" href="../fonts/font-awesome-4.1.0/css/font-awesome.min.css">
<link rel="stylesheet" type="text/css" href="../fonts/eleganticons/et-icons.css">
<link rel="stylesheet" type="text/css" href="../css/jqtree.css">
<link rel="stylesheet" type="text/css" href="../css/idea.css">
<link rel="stylesheet" type="text/css" href="../css/cardio.css">
<script type="text/javascript">
<!-- Matomo -->
var _paq = window._paq = window._paq || [];
/* tracker methods like "setCustomDimension" should be called before "trackPageView" */
/* We explicitly disable cookie tracking to avoid privacy issues */
_paq.push(['disableCookies']);
_paq.push(['trackPageView']);
_paq.push(['enableLinkTracking']);
(function () {
var u = "//matomo.privacy.apache.org/";
_paq.push(['setTrackerUrl', u + 'matomo.php']);
_paq.push(['setSiteId', '5']);
var d = document, g = d.createElement('script'), s = d.getElementsByTagName('script')[0];
g.async = true;
g.src = u + 'matomo.js';
s.parentNode.insertBefore(g, s);
})();
<!-- End Matomo Code -->
</script>
</head>
<body>
<div class="preloader">
<img src="../img/loader.gif" alt="Preloader image">
</div>
<nav class="navbar">
<div class="container">
<div class="row"> <div class="col-md-12">
<!-- Brand and toggle get grouped for better mobile display -->
<div class="navbar-header">
<button type="button" class="navbar-toggle collapsed" data-toggle="collapse" data-target="#bs-example-navbar-collapse-1">
<span class="sr-only">Toggle navigation</span>
<span class="icon-bar"></span>
<span class="icon-bar"></span>
<span class="icon-bar"></span>
</button>
<a class="navbar-brand" href="/" title="Apache TomEE">
<span>
<img
src="../img/apache_tomee-logo.svg"
onerror="this.src='../img/apache_tomee-logo.jpg'"
height="50"
>
</span>
</a>
</div>
<!-- Collect the nav links, forms, and other content for toggling -->
<div class="collapse navbar-collapse" id="bs-example-navbar-collapse-1">
<ul class="nav navbar-nav navbar-right main-nav">
<li><a href="../docs.html">Documentation</a></li>
<li><a href="../community/index.html">Community</a></li>
<li><a href="../security/security.html">Security</a></li>
<li><a class="btn btn-accent accent-orange no-shadow" href="../download.html">Downloads</a></li>
</ul>
</div>
<!-- /.navbar-collapse -->
</div></div>
</div>
<!-- /.container-fluid -->
</nav>
<div id="main-block" class="container main-block">
<div class="row title">
<div class="col-md-12">
<div class='page-header'>
<h1>Apache TomEE 8.0.14 Release Notes</h1>
</div>
</div>
</div>
<div class="row">
<div class="col-md-12">
<div id="preamble">
<div class="sectionbody">
<div class="paragraph">
<p>Apache TomEE 8.0.14 has been released. It is a maintenance release with some bug fixes and dependencies upgrades.</p>
</div>
<div class="paragraph">
<p>Thank you to everyone who contributed to this release, including all of our users and the people who submitted bug reports, contributed code or documentation enhancements.</p>
</div>
</div>
</div>
<div class="sect1">
<h2 id="_dependency_upgrade">Dependency upgrade</h2>
<div class="sectionbody">
<div class="ulist compact">
<ul>
<li>
<p><a href="https://issues.apache.org/jira/browse/TOMEE-4100">TOMEE-4100</a> XBean 4.22</p>
</li>
<li>
<p><a href="https://issues.apache.org/jira/browse/TOMEE-4126">TOMEE-4126</a> CXF 3.4.10</p>
</li>
<li>
<p><a href="https://issues.apache.org/jira/browse/TOMEE-4086">TOMEE-4086</a> HSQLDB 2.7.1</p>
</li>
<li>
<p><a href="https://issues.apache.org/jira/browse/TOMEE-4170">TOMEE-4170</a> Hibernate 5.6.14</p>
</li>
<li>
<p><a href="https://issues.apache.org/jira/browse/TOMEE-4129">TOMEE-4129</a> Jackson 2.14.1</p>
</li>
<li>
<p><a href="https://issues.apache.org/jira/browse/TOMEE-4173">TOMEE-4173</a> Tomcat 9.0.71</p>
</li>
<li>
<p><a href="https://issues.apache.org/jira/browse/TOMEE-4109">TOMEE-4109</a> Velocity 2.3</p>
</li>
<li>
<p><a href="https://issues.apache.org/jira/browse/TOMEE-4110">TOMEE-4110</a> Woodstox 6.4.0</p>
</li>
<li>
<p><a href="https://issues.apache.org/jira/browse/TOMEE-4111">TOMEE-4111</a> bcel component</p>
</li>
<li>
<p><a href="https://issues.apache.org/jira/browse/TOMEE-4130">TOMEE-4130</a> commons-compress 1.22</p>
</li>
</ul>
</div>
</div>
</div>
<div class="sect1">
<h2 id="_bug">Bug</h2>
<div class="sectionbody">
<div class="ulist compact">
<ul>
<li>
<p><a href="https://issues.apache.org/jira/browse/TOMEE-4120">TOMEE-4120</a> Remote EJB2 BMP Memory Leak</p>
</li>
<li>
<p><a href="https://issues.apache.org/jira/browse/TOMEE-4122">TOMEE-4122</a> Performance Regression in bean resolution in EAR files</p>
</li>
<li>
<p><a href="https://issues.apache.org/jira/browse/TOMEE-4101">TOMEE-4101</a> Typo with EL22Adaptor implementation in openwebbeans.properties</p>
</li>
<li>
<p><a href="https://issues.apache.org/jira/browse/TOMEE-4102">TOMEE-4102</a> TomEE logs SEVERE: Expected ContextBinding to have the method getThreadName()</p>
</li>
<li>
<p><a href="https://issues.apache.org/jira/browse/TOMEE-4106">TOMEE-4106</a> TomEE version no longer appearing at default manager page</p>
</li>
<li>
<p><a href="https://issues.apache.org/jira/browse/TOMEE-4014">TOMEE-4014</a> Unable to see TomEE version in Tomcat home page with Java 17</p>
</li>
<li>
<p><a href="https://issues.apache.org/jira/browse/TOMEE-4108">TOMEE-4108</a> Backport TOMEE-4065: LoginToContinue interceptor fails on custom auth mechanism</p>
</li>
<li>
<p><a href="https://issues.apache.org/jira/browse/TOMEE-3779">TOMEE-3779</a> tomee-embedded-maven-plugin fails with NPE</p>
</li>
</ul>
</div>
</div>
</div>
<div class="sect1">
<h2 id="_improvement">Improvement</h2>
<div class="sectionbody">
<div class="ulist compact">
<ul>
<li>
<p><a href="https://issues.apache.org/jira/browse/TOMEE-4124">TOMEE-4124</a> Remove timing of timing just for logging</p>
</li>
</ul>
</div>
</div>
</div>
<div class="sect1">
<h2 id="_task">Task</h2>
<div class="sectionbody">
<div class="ulist compact">
<ul>
<li>
<p><a href="https://issues.apache.org/jira/browse/TOMEE-4171">TOMEE-4171</a> Apache Parent 29</p>
</li>
<li>
<p><a href="https://issues.apache.org/jira/browse/TOMEE-4172">TOMEE-4172</a> JUnit 5.9.2</p>
</li>
<li>
<p><a href="https://issues.apache.org/jira/browse/TOMEE-4177">TOMEE-4177</a> Patch Plugin 0.10</p>
</li>
</ul>
</div>
</div>
</div>
<div class="sect1">
<h2 id="_documentation">Documentation</h2>
<div class="sectionbody">
<div class="ulist compact">
<ul>
<li>
<p><a href="https://issues.apache.org/jira/browse/TOMEE-4104">TOMEE-4104</a> Documentation Website: XA DataSource Configuration: Bug in MySQL Sample Code</p>
</li>
</ul>
</div>
</div>
</div>
<div class="sect1">
<h2 id="_fixed_common_vulnerabilities_and_exposures_cves">Fixed Common Vulnerabilities and Exposures (CVEs)</h2>
<div class="sectionbody">
<div class="ulist compact">
<ul>
<li>
<p><a href="https://issues.apache.org/jira/browse/TOMEE-4086">TOMEE-4086</a> HSQLDB 2.7.1</p>
</li>
<li>
<p><a href="https://issues.apache.org/jira/browse/TOMEE-4125">TOMEE-4125</a> Update Apache CXF versions to mitigate CVE-2022-46364 and CVE-2022-46363</p>
</li>
<li>
<p><a href="https://issues.apache.org/jira/browse/TOMEE-4103">TOMEE-4103</a> Update woodstox-core to mitigate CVE-2022-40153</p>
</li>
<li>
<p><a href="https://issues.apache.org/jira/browse/TOMEE-4111">TOMEE-4111</a> Upgrade bcel component in TomEE</p>
</li>
<li>
<p><a href="https://issues.apache.org/jira/browse/TOMEE-4176">TOMEE-4176</a> CVE-2022-45143 Apache Tomcat - JsonErrorReportValve injection on TomEE&#8217;s tomcat-websocket.jar</p>
</li>
<li>
<p><a href="https://issues.apache.org/jira/browse/TOMEE-4169">TOMEE-4169</a> SnakeYAML - CVE-2022-1471</p>
</li>
</ul>
</div>
</div>
</div>
<div class="sect1">
<h2 id="_additional_information">Additional Information</h2>
<div class="sectionbody">
<div class="paragraph">
<p><strong>Please note:</strong></p>
</div>
<div class="admonitionblock important">
<table>
<tr>
<td class="icon">
<i class="fa icon-important" title="Important"></i>
</td>
<td class="content">
CVE-2022-1471: Snakeyaml is a transient dependency of <code>jackson-dataformat-yaml</code> (which is used in OpenAPI). According to the Jackson people, they are <strong>not</strong> affected: <a href="https://github.com/FasterXML/jackson-dataformats-text/issues/361" class="bare">https://github.com/FasterXML/jackson-dataformats-text/issues/361</a>
</td>
</tr>
</table>
</div>
</div>
</div>
</div>
</div>
</div>
<div style="margin-bottom: 30px;"></div>
<footer>
<div class="container">
<div class="row">
<div class="col-sm-6 text-center-mobile">
<h3 class="white">Be simple. Be certified. Be Tomcat.</h3>
<h5 class="light regular light-white">"A good application in a good server"</h5>
<ul class="social-footer">
<li><a href="https://www.facebook.com/ApacheTomEE/"><i class="fa fa-facebook"></i></a></li>
<li><a href="https://twitter.com/apachetomee"><i class="fa fa-twitter"></i></a></li>
</ul>
<h5 class="light regular light-white">
<a href="../privacy-policy.html" class="white">Privacy Policy</a>
</h5>
</div>
<div class="col-sm-6 text-center-mobile">
<div class="row opening-hours">
<div class="col-sm-3 text-center-mobile">
<h5><a href="../latest/docs/" class="white">Documentation</a></h5>
<ul class="list-unstyled">
<li><a href="../latest/docs/admin/configuration/index.html" class="regular light-white">How to configure</a></li>
<li><a href="../latest/docs/admin/file-layout.html" class="regular light-white">Dir. Structure</a></li>
<li><a href="../latest/docs/developer/testing/index.html" class="regular light-white">Testing</a></li>
<li><a href="../latest/docs/admin/cluster/index.html" class="regular light-white">Clustering</a></li>
</ul>
</div>
<div class="col-sm-3 text-center-mobile">
<h5><a href="../latest/examples/" class="white">Examples</a></h5>
<ul class="list-unstyled">
<li><a href="../latest/examples/simple-cdi-interceptor.html" class="regular light-white">CDI Interceptor</a></li>
<li><a href="../latest/examples/rest-cdi.html" class="regular light-white">REST with CDI</a></li>
<li><a href="../latest/examples/ejb-examples.html" class="regular light-white">EJB</a></li>
<li><a href="../latest/examples/jsf-managedBean-and-ejb.html" class="regular light-white">JSF</a></li>
</ul>
</div>
<div class="col-sm-3 text-center-mobile">
<h5><a href="../community/index.html" class="white">Community</a></h5>
<ul class="list-unstyled">
<li><a href="../community/contributors.html" class="regular light-white">Contributors</a></li>
<li><a href="../community/social.html" class="regular light-white">Social</a></li>
<li><a href="../community/sources.html" class="regular light-white">Sources</a></li>
</ul>
</div>
<div class="col-sm-3 text-center-mobile">
<h5><a href="../security/index.html" class="white">Security</a></h5>
<ul class="list-unstyled">
<li><a href="https://apache.org/security" target="_blank" class="regular light-white">Apache Security</a></li>
<li><a href="https://apache.org/security/projects.html" target="_blank" class="regular light-white">Security Projects</a></li>
<li><a href="https://cve.mitre.org" target="_blank" class="regular light-white">CVE</a></li>
</ul>
</div>
</div>
</div>
</div>
<div class="row bottom-footer text-center-mobile">
<div class="col-sm-12 light-white">
<p>Copyright &copy; 1999-2022 The Apache Software Foundation, Licensed under the Apache License, Version 2.0. Apache TomEE, TomEE, Apache, the Apache feather logo, and the Apache TomEE project logo are trademarks of The Apache Software Foundation. All other marks mentioned may be trademarks or registered trademarks of their respective owners.</p>
</div>
</div>
</div>
</footer>
<!-- Holder for mobile navigation -->
<div class="mobile-nav">
<ul>
<li><a hef="../latest/docs/admin/index.html">Administrators</a>
<li><a hef="../latest/docs/developer/index.html">Developers</a>
<li><a hef="../latest/docs/advanced/index.html">Advanced</a>
<li><a hef="../community/index.html">Community</a>
</ul>
<a href="#" class="close-link"><i class="arrow_up"></i></a>
</div>
<!-- Scripts -->
<script src="../js/jquery-1.11.1.min.js"></script>
<script src="../js/owl.carousel.min.js"></script>
<script src="../js/bootstrap.min.js"></script>
<script src="../js/wow.min.js"></script>
<script src="../js/typewriter.js"></script>
<script src="../js/jquery.onepagenav.js"></script>
<script src="../js/tree.jquery.js"></script>
<script src="../js/highlight.pack.js"></script>
<script src="../js/main.js"></script>
</body>
</html>