Uploaded image for project: 'Qpid'
  1. Qpid
  2. QPID-8600

[Broker-J] File path validation in management-http plugin

    XMLWordPrintableJSON

Details

    • Improvement
    • Status: Closed
    • Minor
    • Resolution: Fixed
    • qpid-java-broker-8.0.6
    • qpid-java-broker-9.0.0
    • Broker-J
    • None

    Description

      HTTP management plugin initiates a network connection in classes FileServlet to a third-party system using user-controlled data for resource URI. This vulnerability may be leveraged to send a request on behalf of the web server since the request will originate from the web server's internal IP address.

      Attachments

        Activity

          People

            Unassigned Unassigned
            daniel.kirilyuk Daniil Kirilyuk
            Votes:
            0 Vote for this issue
            Watchers:
            3 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: