View Issue Details

IDProjectCategoryView StatusLast Update
0006852SymmetricDS ProBugpublic2025-05-05 16:34
Reporterelong Assigned Toelong  
Prioritynormal 
Status closedResolutionfixed 
Product Version3.15.0 
Target Version3.15.16Fixed in Version3.15.16 
Summary0006852: Disallow access to WEB-INF
DescriptionOn Windows server with standalone deployment based on Jetty, it is possible to retrieve URLs under WEB-INF by adding a period to the path. An actor could gain access to JAR files in WEB-INF/lib, including symmetric-pro JAR files. However, these files are already publicly available and obfuscated. The requests do not work on Mac or Linux servers, only Windows.

Steps To Reproducehttp://localhost/WEB-INF./web.xml
Tagssecurity

Relationships

related to 0006853 closedelong Disallow access to WEB-INF 

Activities

pbelov

2025-05-05 16:34

manager   ~0002879

Included in the 3.15.16 release

Issue History

Date Modified Username Field Change
2025-04-28 12:53 elong New Issue
2025-04-28 12:53 elong Status new => assigned
2025-04-28 12:53 elong Assigned To => elong
2025-04-28 12:53 elong Tag Attached: security
2025-04-28 12:58 elong Status assigned => resolved
2025-04-28 12:58 elong Resolution open => fixed
2025-04-28 12:58 elong Fixed in Version => 3.15.16
2025-04-28 12:58 elong Issue cloned: 0006853
2025-04-28 12:58 elong Relationship added related to 0006853
2025-05-05 16:34 pbelov Note Added: 0002879
2025-05-05 16:34 pbelov Status resolved => closed