Browse Source

Improve static resource path check

(cherry picked from commit 2697425)
pull/1103/head
Rossen Stoyanchev 10 years ago committed by Juergen Hoeller
parent
commit
fc37824bc0
  1. 4
      spring-webmvc/src/main/java/org/springframework/web/servlet/resource/ResourceHttpRequestHandler.java

4
spring-webmvc/src/main/java/org/springframework/web/servlet/resource/ResourceHttpRequestHandler.java

@ -1,5 +1,5 @@ @@ -1,5 +1,5 @@
/*
* Copyright 2002-2014 the original author or authors.
* Copyright 2002-2016 the original author or authors.
*
* Licensed under the Apache License, Version 2.0 (the "License");
* you may not use this file except in compliance with the License.
@ -281,7 +281,7 @@ public class ResourceHttpRequestHandler extends WebContentGenerator implements H @@ -281,7 +281,7 @@ public class ResourceHttpRequestHandler extends WebContentGenerator implements H
return true;
}
}
if (path.contains("../")) {
if (path.contains("..")) {
path = StringUtils.cleanPath(path);
if (path.contains("../")) {
if (logger.isTraceEnabled()) {

Loading…
Cancel
Save