Uploaded image for project: 'Tapestry'
  1. Tapestry
  2. TAPESTRY-1175

security flaw - unprotected asset regexp paths allow access to other things

    XMLWordPrintableJSON

Details

    • Bug
    • Status: Resolved
    • Blocker
    • Resolution: Fixed
    • 4.1.1
    • 4.1.1
    • Framework
    • None
    • any

    Description

      As pointed out on the dev list, the current basic strings "dojo/" and "tapestry/" aren't enough to prevent access to other resources. (such as a class in a package like foo.tapestry.pages )

      Investigate using the beginning of line specifier "^" or whatever else works. This definitely needs to be fixed before 4.1.1 goes out.

      Attachments

        Activity

          People

            jkuhnert Jesse Kuhnert
            jkuhnert Jesse Kuhnert
            Votes:
            0 Vote for this issue
            Watchers:
            0 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: