tomcat-dev mailing list archives

Site index · List index
Message view « Date » · « Thread »
Top « Date » · « Thread »
From "Greg Wetmore" <>
Subject Access WEB-INF through the JK NSAPI connector
Date Tue, 11 Jul 2006 14:52:08 GMT
I am looking at:

I do not see any code blocks specifically checking for and rejecting
requests to WEB-INF/* or META-INF/*.

This seems different in design from the Apache or IIS filters - for example:
   Apache 2.0 - mod_jk.c:2575
   IIS - jk_isapi_plugin.c:869

Does this represent a security flaw or a bug?

In the mean time I have configured iplanet to reject requests to WEB-INF:
  PathCheck fn="deny-existence" path="*/WEB-INF/*"

To unsubscribe, e-mail:
For additional commands, e-mail:

View raw message