Uploaded image for project: 'ActiveMQ'
  1. ActiveMQ
  2. AMQ-7209

[STOMP] SecurityException stack trace should not be in error frames

    XMLWordPrintableJSON

    Details

    • Type: Bug
    • Status: Resolved
    • Priority: Major
    • Resolution: Fixed
    • Affects Version/s: 5.15.0
    • Fix Version/s: 5.16.0
    • Component/s: Broker, STOMP
    • Labels:
      None

      Description

      The stack trace of all exceptions is returned in the body of error frames. For security exceptions this can leak some information about the implementation and configured plugins which is not sensible.

      the stack trace should not be present for any SecurityException, just the exception message.

        Attachments

          Activity

            People

            • Assignee:
              gtully Gary Tully
              Reporter:
              gtully Gary Tully
            • Votes:
              0 Vote for this issue
              Watchers:
              2 Start watching this issue

              Dates

              • Created:
                Updated:
                Resolved: