Details
-
Improvement
-
Status: Closed
-
Minor
-
Resolution: Fixed
-
qpid-java-broker-8.0.6
-
None
Description
HTTP management plugin initiates a network connection in classes FileServlet to a third-party system using user-controlled data for resource URI. This vulnerability may be leveraged to send a request on behalf of the web server since the request will originate from the web server's internal IP address.