CVE 2016 6801.patch | (download) |
jackrabbit-spi2dav/src/main/java/org/apache/jackrabbit/spi2davex/PostMethod.java |
1 1 + 0 - 0 !
jackrabbit-webdav/src/main/java/org/apache/jackrabbit/webdav/DavResource.java |
2 1 + 1 - 0 !
jackrabbit-webdav/src/main/java/org/apache/jackrabbit/webdav/server/AbstractWebdavServlet.java |
3 1 + 2 - 0 !
jackrabbit-webdav/src/main/java/org/apache/jackrabbit/webdav/util/CSRFUtil.java |
83 71 + 12 - 0 !
4 files changed, 74 insertions(+), 15 deletions(-) |
cve-2016-6801
The CSRF content-type check for POST requests did not handle missing
Content-Type header fields, nor variations in field values with respect to
upper/lower case or optional parameters. This could be exploited to create a
resource via CSRF.
Backported to the 2.3 branch.
|