This is an automated email from the ASF dual-hosted git repository. rmaucher pushed a commit to branch 9.0.x in repository https://gitbox.apache.org/repos/asf/tomcat.git
commit a3c0bc010bb8a17750dd251024c3a8be7632c882 Author: opencode <[email protected]> AuthorDate: Wed Sep 30 16:24:53 2026 +0200 Use an instanceof check when instantiating the configured randomClass in CsrfPreventionFilterBase.init() so a class that is not a Random subclass produces the intended ServletException rather than a raw ClassCastException --- java/org/apache/catalina/filters/CsrfPreventionFilterBase.java | 7 ++++++- 1 file changed, 6 insertions(+), 1 deletion(-) diff --git a/java/org/apache/catalina/filters/CsrfPreventionFilterBase.java b/java/org/apache/catalina/filters/CsrfPreventionFilterBase.java index e8b7870814..b5abf953da 100644 --- a/java/org/apache/catalina/filters/CsrfPreventionFilterBase.java +++ b/java/org/apache/catalina/filters/CsrfPreventionFilterBase.java @@ -88,7 +88,12 @@ public abstract class CsrfPreventionFilterBase extends FilterBase { try { Class<?> clazz = Class.forName(randomClass); - randomSource = (Random) clazz.getConstructor().newInstance(); + Object instance = clazz.getConstructor().newInstance(); + if (instance instanceof Random random) { + randomSource = random; + } else { + throw new ServletException(sm.getString("csrfPrevention.invalidRandomClass", randomClass)); + } } catch (ReflectiveOperationException e) { throw new ServletException(sm.getString("csrfPrevention.invalidRandomClass", randomClass), e); } --------------------------------------------------------------------- To unsubscribe, e-mail: [email protected] For additional commands, e-mail: [email protected]
