-
Bug
-
Resolution: Done
-
Critical
-
JWS 3.1.0 CR4
-
None
-
Release Notes
-
-
-
-
-
-
As a result of CVE-2016-6816 unencoded characters are rejected as invalid. Unfortunately some clients are still behaving that way and were being rejected by tomcat. An option has been added that will allow you to accept unencoded {, }, and | characters.
We need to backport the following to limit customer issues from the CVE-2016-6816 fix:
https://bz.apache.org/bugzilla/show_bug.cgi?id=60594
tomcat7
http://svn.apache.org/r1782043
http://svn.apache.org/r1782246
tomcat8
http://svn.apache.org/r1782041
http://svn.apache.org/r1782243
- is cloned by
-
JWS-720 [GSS](3.1.0 one-off) RFC 7230/3986 url requirement that prevents unencoded curly braces should be optional, since it breaks existing sites
- Closed
- links to