View Issue Details

IDProjectCategoryView StatusLast Update
0006853SymmetricDS ProBugpublic2025-04-28 12:58
Reporterelong Assigned Toelong  
Prioritynormal 
Status resolvedResolutionfixed 
Product Version3.16.0 
Target Version3.16.2Fixed in Version3.16.2 
Summary0006853: Disallow access to WEB-INF
DescriptionOn Windows server with standalone deployment based on Jetty, it is possible to retrieve URLs under WEB-INF by adding a period to the path. An actor could gain access to JAR files in WEB-INF/lib, including symmetric-pro JAR files. However, these files are already publicly available and obfuscated. The requests do not work on Mac or Linux servers, only Windows.

Steps To Reproducehttp://localhost/WEB-INF./web.xml
Tagssecurity

Relationships

related to 0006852 resolvedelong Disallow access to WEB-INF 

Activities

There are no notes attached to this issue.

Issue History

Date Modified Username Field Change
2025-04-28 12:58 elong New Issue
2025-04-28 12:58 elong Status new => assigned
2025-04-28 12:58 elong Assigned To => elong
2025-04-28 12:58 elong Tag Attached: security
2025-04-28 12:58 elong Issue generated from: 0006852
2025-04-28 12:58 elong Relationship added related to 0006852
2025-04-28 12:58 elong Status assigned => resolved
2025-04-28 12:58 elong Resolution open => fixed
2025-04-28 12:58 elong Fixed in Version => 3.16.2