Details
-
Improvement
-
Status: Closed
-
Minor
-
Resolution: Fixed
-
qpid-java-broker-8.0.6
-
None
Description
Java broker HTTP management plugin invokes in filter RewriteRequestForUncompressedJavascript a server side forward using a path built with unvalidated input. This could allow an attacker to download application binaries or view arbitrary files within protected directories.