Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Adding ReDoS warning/documentation to RewriteValve #149

Closed
wants to merge 2 commits into from

Conversation

groundboi
Copy link

After reporting a potential DoS in "Rewrite Rules" to the Tomcat security team, it was decided that there was no bug in Tomcat itself, but rather in how a user sets up their Tomcat server. Thus, I was instructed by the security team to create a PR for updated documentation to better educate users on appropriate usage of Rewrite Rules. This commit added javadoc comments for the RewriteValve class, as instructed.

Furthermore, I'd like to update the documentation on this page as well, however I cannot find a mechanism to do so: https://tomcat.apache.org/tomcat-9.0-doc/rewrite.html

@markt-asf
Copy link
Contributor

That page is generated from this file:
https://github.com/apache/tomcat/blob/master/webapps/docs/rewrite.xml

@groundboi
Copy link
Author

Great, thanks. I just included a statement for the documentation in there as well.

@markt-asf
Copy link
Contributor

Thanks. I applied the patch along with a couple of formatting tweaks, a cross-reference from the security how to page and a change log entry (giving you credit for the change).

@markt-asf markt-asf closed this Apr 7, 2019
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
2 participants