Uploaded image for project: 'CXF'
  1. CXF
  2. CXF-4056

Faults on server are echoing headers back to the client

    XMLWordPrintableJSON

Details

    • Bug
    • Status: Closed
    • Major
    • Resolution: Fixed
    • 2.5.2
    • 2.3.10, 2.4.7, 2.5.3
    • Soap Binding
    • None
    • Unknown

    Description


      The SoapHeaderOutFilterInterceptor that filters out the incoming headers is only installed on the Out chain. It's not installed on the OutFault chain. Thus, all the incoming headers are echoed back to the client which could result in WS-Addressing issues, security issues, etc...

      Attachments

        Activity

          People

            dkulp Daniel Kulp
            dkulp Daniel Kulp
            Votes:
            0 Vote for this issue
            Watchers:
            0 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: