Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Where Can I Report Security Vulnerability? #981

Closed
orangetw opened this issue Feb 25, 2018 · 8 comments
Closed

Where Can I Report Security Vulnerability? #981

orangetw opened this issue Feb 25, 2018 · 8 comments

Comments

@orangetw
Copy link

HI, I found a vulnerability and followed the steps, and sent mail to people on this page.

But seems one of these mail addresses are not exists and there are no reply for 3 days.

Could you check the mail box? Thanks!

@tipsy
Copy link
Contributor

tipsy commented Feb 25, 2018

I can't find the email, but I've messaged @perwendel.

@orangetw
Copy link
Author

orangetw commented Feb 25, 2018 via email

@tipsy
Copy link
Contributor

tipsy commented Feb 25, 2018

That would explain it... Should be [email protected].

@orangetw
Copy link
Author

orangetw commented Feb 25, 2018 via email

@perwendel
Copy link
Owner

I've released the mail. I'm on a long weekend vacation and will have a look tomorrow!

@perwendel
Copy link
Owner

*received

@perwendel
Copy link
Owner

I've checked the issue. We will create a fix ASAP. Thanks for finding and reporting!

perwendel added a commit that referenced this issue Mar 6, 2018
perwendel added a commit that referenced this issue Mar 6, 2018
@perwendel
Copy link
Owner

Fixed! Thanks for reporting and investigating @orangetw

perwendel added a commit that referenced this issue Mar 7, 2018
perwendel added a commit that referenced this issue Mar 7, 2018
jsiebahn pushed a commit to jsiebahn/spark that referenced this issue Apr 6, 2018
With perwendel#981 the ClassPathResource drops paths containing `META-INF` and
`WEB-INF`. The Servlet Spec defines `/META-INF/resources` as a default
resource path to include static resources from libraries.

This commit adds an exception for this defined path.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants