This is an automated email from the ASF dual-hosted git repository. rmaucher pushed a commit to branch 10.1.x in repository https://gitbox.apache.org/repos/asf/tomcat.git
commit db6fe77aebbc113c44e58654a80100d57bf4f633 Author: opencode <[email protected]> AuthorDate: Wed Sep 30 16:24:53 2026 +0200 Use an instanceof check when instantiating the configured randomClass in CsrfPreventionFilterBase.init() so a class that is not a Random subclass produces the intended ServletException rather than a raw ClassCastException --- java/org/apache/catalina/filters/CsrfPreventionFilterBase.java | 7 ++++++- 1 file changed, 6 insertions(+), 1 deletion(-) diff --git a/java/org/apache/catalina/filters/CsrfPreventionFilterBase.java b/java/org/apache/catalina/filters/CsrfPreventionFilterBase.java index 15d2e00c67..a899aa71da 100644 --- a/java/org/apache/catalina/filters/CsrfPreventionFilterBase.java +++ b/java/org/apache/catalina/filters/CsrfPreventionFilterBase.java @@ -88,7 +88,12 @@ public abstract class CsrfPreventionFilterBase extends FilterBase { try { Class<?> clazz = Class.forName(randomClass); - randomSource = (Random) clazz.getConstructor().newInstance(); + Object instance = clazz.getConstructor().newInstance(); + if (instance instanceof Random random) { + randomSource = random; + } else { + throw new ServletException(sm.getString("csrfPrevention.invalidRandomClass", randomClass)); + } } catch (ReflectiveOperationException e) { throw new ServletException(sm.getString("csrfPrevention.invalidRandomClass", randomClass), e); } --------------------------------------------------------------------- To unsubscribe, e-mail: [email protected] For additional commands, e-mail: [email protected]
