Details
-
Bug
-
Status: Closed
-
Major
-
Resolution: Fixed
-
2.5.2
-
None
-
Unknown
Description
The SoapHeaderOutFilterInterceptor that filters out the incoming headers is only installed on the Out chain. It's not installed on the OutFault chain. Thus, all the incoming headers are echoed back to the client which could result in WS-Addressing issues, security issues, etc...