This content has been marked as final.
Show 4 replies
-
1. Re: How do I prevent access to WEB-INF via HTTP GET in WildFly 10?
jaikiran Nov 30, 2018 9:09 AM (in response to sjeaves2)1 of 1 people found this helpfulThat's clearly a bug. Having said that, I remember such issues have been fixed in newer releases of WildFly. Have you tried upgrading to latest released WildFly (14 currently) and see if it's still reproducible?
-
2. Re: How do I prevent access to WEB-INF via HTTP GET in WildFly 10?
msystems Nov 30, 2018 9:18 AM (in response to jaikiran)1 of 1 people found this helpfulI'm using WildFly 14.0.1 and it's not possible to access the WEB-INF with a GET request with a relative pathname like http://myhost.com:8080/ServletName/..\WEB-INF\web.xml - you will get an '404 - Not Found'.
-
3. Re: How do I prevent access to WEB-INF via HTTP GET in WildFly 10?
sjeaves2 Nov 30, 2018 9:25 AM (in response to jaikiran)I will try an upgrade and see how that works.
-
4. Re: How do I prevent access to WEB-INF via HTTP GET in WildFly 10?
sjeaves2 Nov 30, 2018 11:34 AM (in response to msystems)Thanks for the confirmation. I'm not sure that we are able to move to a higher version here yet, but it is good to know that this is a bug in WildFly and not in our code.