marcsaeg01/07/16 21:25:56
Modified:src/share/org/apache/tomcat/core Tag: tomcat_32
ContextManager.java
src/share/org/apache/tomcat/request Tag: tomcat_32
AccessInterceptor.java
src/share/org/apache/tomcat/util
marcsaeg01/04/07 18:37:57
Modified:src/share/org/apache/tomcat/core Tag: tomcat_32 Context.java
src/share/org/apache/tomcat/facade Tag: tomcat_32
ServletContextFacade.java
src/share/org/apache/tomcat/util Tag: tomcat_32 URLUtil.java
marcsaeg01/04/06 18:07:19
Modified:src/share/org/apache/tomcat/core Tag: tomcat_32 Context.java
src/share/org/apache/tomcat/util Tag: tomcat_32 URLUtil.java
Log:
Fixes a security hole caused by URLs being decoded twice. The second
decoding is happening when an Inpu