https://issues.apache.org/bugzilla/show_bug.cgi?id=55776
Mark Thomas <ma...@apache.org> changed: What |Removed |Added ---------------------------------------------------------------------------- Status|REOPENED |RESOLVED Resolution|--- |FIXED --- Comment #10 from Mark Thomas <ma...@apache.org> --- I'm changing this back to fixed. Accepting /../ and /./ in the path is something that previous Tomcat versions have done and - based on this bug report - at least one user is depending on it (which probably means there are more). Given that the feature exists and has been used, I don't think we should remove it (or even provide an option to disable it) solely because the standard class loader doesn't permit it. If there is a use case for disabling it then I'd be OK with adding an option to do that but that would be best handled under a new enhancement request. -- You are receiving this mail because: You are the assignee for the bug. --------------------------------------------------------------------- To unsubscribe, e-mail: dev-unsubscr...@tomcat.apache.org For additional commands, e-mail: dev-h...@tomcat.apache.org