From 013779aedf93a6f6ff878c457de53e729540c252 Mon Sep 17 00:00:00 2001 From: vasraz Date: Wed, 7 Sep 2022 18:45:20 +0100 Subject: Fix high-severity bug 'application exposed to path traversal attack' Signed-off-by: Vasyl Razinkov Change-Id: I7f4b1e8d083cc39f8e57dcedddecc6af56fdc9c2 Issue-ID: SDC-4169 --- catalog-fe/src/main/webapp/WEB-INF/web.xml | 230 +++++++++++++++-------------- 1 file changed, 118 insertions(+), 112 deletions(-) (limited to 'catalog-fe') diff --git a/catalog-fe/src/main/webapp/WEB-INF/web.xml b/catalog-fe/src/main/webapp/WEB-INF/web.xml index 8f64a2b336..de133ac8ec 100644 --- a/catalog-fe/src/main/webapp/WEB-INF/web.xml +++ b/catalog-fe/src/main/webapp/WEB-INF/web.xml @@ -1,115 +1,121 @@ - - - - jersey - org.glassfish.jersey.servlet.ServletContainer - - jersey.config.server.provider.packages - org.openecomp.sdc.fe.servlets - - - - jersey.config.server.provider.classnames - org.glassfish.jersey.media.multipart.MultiPartFeature - - - com.sun.jersey.api.json.POJOMappingFeature - true - - 1 - true - - - - jersey - /rest/* - - - - ViewStatusMessages - ch.qos.logback.classic.ViewStatusMessagesServlet + + + + jersey + org.glassfish.jersey.servlet.ServletContainer + + jersey.config.server.provider.packages + org.openecomp.sdc.fe.servlets + + + + jersey.config.server.provider.classnames + org.glassfish.jersey.media.multipart.MultiPartFeature + + + com.sun.jersey.api.json.POJOMappingFeature + true + + 1 true - - - - ViewStatusMessages - /lbClassicStatus - - - - - FeProxy - org.openecomp.sdc.fe.servlets.FeProxyServlet - - 1 - true - - - - - - FeProxy - /feProxy/* - - - - Portal - org.openecomp.sdc.fe.servlets.PortalServlet - true - - - - Portal - /portal - - - - - AuditLogServletFilter - org.onap.logging.filter.base.AuditLogServletFilter - true - - - - - - - - - - - - - - - gzipFilter - org.openecomp.sdc.fe.filters.GzipFilter - true - - - - AuditLogServletFilter - /* - - - - - - - - - gzipFilter - *.jsgz - - - - org.openecomp.sdc.fe.listen.FEAppContextListener - - - - index.html - + + + + jersey + /rest/* + + + + ViewStatusMessages + ch.qos.logback.classic.ViewStatusMessagesServlet + true + + + + ViewStatusMessages + /lbClassicStatus + + + + + FeProxy + org.openecomp.sdc.fe.servlets.FeProxyServlet + + 1 + true + + + + + + FeProxy + /feProxy/* + + + + Portal + org.openecomp.sdc.fe.servlets.PortalServlet + true + + + + Portal + /portal + + + + org.eclipse.jetty.servlet.Default.dirAllowed + false + + + + + AuditLogServletFilter + org.onap.logging.filter.base.AuditLogServletFilter + true + + + + + + + + + + + + + + + gzipFilter + org.openecomp.sdc.fe.filters.GzipFilter + true + + + + AuditLogServletFilter + /* + + + + + + + + + gzipFilter + *.jsgz + + + + org.openecomp.sdc.fe.listen.FEAppContextListener + + + + index.html + -- cgit 1.2.3-korg