Browse Source

Improve static resource path check

pull/1091/merge
Rossen Stoyanchev 10 years ago
parent
commit
775ffbe10b
  1. 2
      spring-webmvc/src/main/java/org/springframework/web/servlet/resource/ResourceHttpRequestHandler.java

2
spring-webmvc/src/main/java/org/springframework/web/servlet/resource/ResourceHttpRequestHandler.java

@ -487,7 +487,7 @@ public class ResourceHttpRequestHandler extends WebContentGenerator @@ -487,7 +487,7 @@ public class ResourceHttpRequestHandler extends WebContentGenerator
return true;
}
}
if (path.contains("../")) {
if (path.contains("..")) {
path = StringUtils.cleanPath(path);
if (path.contains("../")) {
if (logger.isTraceEnabled()) {

Loading…
Cancel
Save