Details
-
Bug
-
Status: Closed
-
Minor
-
Resolution: Fixed
-
5.1.0.5
-
None
Description
The DefaultRequestExceptionHandler sets the X-Tapestry-ErrorMessage header but fails to sanitize or encode the error message. This enables an attacker to inject malicious HTTP headers or to provide a 2nd HTTP response.