Skip to content

[RESTEASY-1704] CVE-2017-7561 resteasy: Vary header not added by CORS filter leading to cache poisoning#1301

Merged
asoldano merged 1 commit intoresteasy:3.0from
yersan:bugs/JBEAP-12820
Nov 7, 2017
Merged

[RESTEASY-1704] CVE-2017-7561 resteasy: Vary header not added by CORS filter leading to cache poisoning#1301
asoldano merged 1 commit intoresteasy:3.0from
yersan:bugs/JBEAP-12820

Conversation

@yersan
Copy link
Copy Markdown
Contributor

@yersan yersan commented Oct 9, 2017

Issue: https://issues.jboss.org/browse/JBEAP-12820
Upstream Issue: https://issues.jboss.org/browse/RESTEASY-1704
Upstream PR: #1258

Backporting fix for RESTEASY-1704 to branch 3.0 (thus for EAP 7.1.z stream)

@asoldano asoldano merged commit fd66aad into resteasy:3.0 Nov 7, 2017
@yersan yersan deleted the bugs/JBEAP-12820 branch November 8, 2017 15:02
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants