-
Bug
-
Resolution: Done
-
Major
-
None
-
None
-
None
13.8.4 "Uncovered HTTP Protocol Methods":
When HTTP methods are not enumerated within a security-constraint, the protections defined by the constraint apply to the complete set of HTTP (extension) methods. In that case, there are no uncovered HTTP methods at all request URLs for which a url-pattern of the security-constraint is a best match.
- causes
-
UNDERTOW-2209 deny-uncovered-methods grants access to forbidden methods when default security is blank
- Closed
- is incorporated by
-
JBEAP-23166 [GSS](7.4.z) UNDERTOW-2211 <deny-uncovered-http-methods /> causes forbidden access for anonymous resources access.
- Closed
-
WFCORE-6217 Upgrade Undertow from 2.3.0.Final to 2.3.4.Final
- Closed
- relates to
-
UNDERTOW-2211 deny-uncovered-methods regards omitted methods as covered
- Resolved
-
UNDERTOW-2213 Revert deny-uncovered-methods fix for corner case
- Closed