[thredds] Tomcat Ghostcat Vulnerability

I am surprised this hasn't hit this list already:

"Ghostcat" is a new security vulnerability in Tomcat's AJP Connector that 
potentially allows attackers to take over the server. You can read more about 
the problem at

Updates are available for the recent versions of Tomcat to fix this.  We have 
updated 2 TDS to Tomcat 8: 8.5.51 with no issues that I can see,  but ten again 
we aren't using AJP.


