You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
I had searched in the DSIP and found no similar DSIP.
Motivation
DS was scanned for TRACE vulnerability。An attacker exploiting a TRACE request, in combination with other browser-side vulnerabilities, could potentially conduct a cross-site scripting attack to obtain sensitive information, such as authentication information in a cookie, which would be used in other types of attacks.
Design Detail
jetty TRACE requests can be disabled via a configuration option
ruanwenjun
changed the title
[DSIP-]How to disallow or disable HTTP TRACE requests in jetty via configuration
[DSIP-37]How to disallow or disable HTTP TRACE requests in jetty via configuration
May 8, 2024
+1, directly disable trace LGTM, we don't need to add a config to control this, are you willing to submit PR?
ruanwenjun
changed the title
[DSIP-37]How to disallow or disable HTTP TRACE requests in jetty via configuration
[DSIP-37] Disable HTTP TRACE requests in jetty via configuration
May 15, 2024
Search before asking
Motivation
DS was scanned for TRACE vulnerability。An attacker exploiting a TRACE request, in combination with other browser-side vulnerabilities, could potentially conduct a cross-site scripting attack to obtain sensitive information, such as authentication information in a cookie, which would be used in other types of attacks.
Design Detail
jetty TRACE requests can be disabled via a configuration option
Compatibility, Deprecation, and Migration Plan
No response
Test Plan
No response
Code of Conduct
The text was updated successfully, but these errors were encountered: