Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Security issue - source files visible via browser #837

Open
raffig opened this issue Nov 3, 2020 · 0 comments
Open

Security issue - source files visible via browser #837

raffig opened this issue Nov 3, 2020 · 0 comments

Comments

@raffig
Copy link

raffig commented Nov 3, 2020

Hi there!

There is a potential security issue. Due to default configuration of JoinFaces source files are visible directly through the browser. It is related to their location expected by join faces (META-INF/resources). For example in joinfaces-maven-jar-example one can easily access any file like:
http://localhost:8080/tags/tags.taglib.xml
http://localhost:8080/cc/textComponent.xhtml

Please change the default location (/src/main/webapp?) or at least provide a setting to alter this default location.

This issue has been also reported in here:
joinfaces/joinfaces-maven-jar-example#291

Similar issue, from different perspective, has also been reported here:
#315

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant