RE: Malicious Headers

2020-03-27 Thread George Stanchev
:55 AM To: dev@tomcat.apache.org Subject: Malicious Headers We are using Fortify, which is a static code analysis tool to find vulnerabilities in your code and it's saying that code might be susceptible to malicious header injection, such as CRLF. However, it also says that "Many o

Malicious Headers

2020-03-27 Thread Victor Rodriguez
We are using Fortify, which is a static code analysis tool to find vulnerabilities in your code and it's saying that code might be susceptible to malicious header injection, such as CRLF. However, it also says that "Many of today's modern application servers will prevent the injection of malicious