Uploaded image for project: 'Tapestry 5'
  1. Tapestry 5
  2. TAP5-1004

X-Tapestry-ErrorMessage may lead to HTTP Response Splitting

    XMLWordPrintableJSON

Details

    • Bug
    • Status: Closed
    • Minor
    • Resolution: Fixed
    • 5.1.0.5
    • 5.2.1
    • tapestry-core
    • None

    Description

      The DefaultRequestExceptionHandler sets the X-Tapestry-ErrorMessage header but fails to sanitize or encode the error message. This enables an attacker to inject malicious HTTP headers or to provide a 2nd HTTP response.

      Attachments

        Activity

          People

            hlship Howard Lewis Ship
            prehrl Paul Rehrl
            Votes:
            2 Vote for this issue
            Watchers:
            1 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: