https://bz.apache.org/bugzilla/show_bug.cgi?id=59243

--- Comment #5 from Christopher Schultz <[email protected]> ---
(In reply to Violeta Georgieva from comment #4)
> Fix your application.

Correct. The path-traversal vulnerability has been introduced by your own
application, not by Tomcat.

One of the best ways to prevent this kind of thing is to white-list certain
paths that are acceptable (and won't ever cause a path-traversal issue).

-- 
You are receiving this mail because:
You are the assignee for the bug.

---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to