Uploaded image for project: 'Jackrabbit Content Repository'
  1. Jackrabbit Content Repository
  2. JCR-2953

PathParser accepts illegal paths containing curly brackets

    XMLWordPrintableJSON

Details

    Description

      o.a.jackrabbit.spi.commons.conversion.PathParser accepts the following path:

      "/public/.

      {.}

      /private"

      the normalized resulting Path object represents "/private"

      that's a potential security risk.

      Attachments

        Activity

          People

            angela Angela Schreiber
            stefan@jira Stefan Guggisberg
            Votes:
            0 Vote for this issue
            Watchers:
            0 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: