jboss-fuse / fuse

JBoss Fuse is an open source ESB with capabilities based on Apache Camel, Apache CXF, Apache ActiveMQ, Apache Karaf and Fabric8 in a single integrated distribution.
Apache License 2.0
136 stars 98 forks source link

ENTESB-6478 - XSS vulnerability in Hawtio (proxy servlet) #365

Closed tadayosi closed 7 years ago

tadayosi commented 7 years ago

https://issues.jboss.org/browse/ENTESB-6478 https://issues.jboss.org/browse/PATCH-1676

See also: jboss-fuse/hawtio/pull/278

tadayosi commented 7 years ago

@kevinearls @grgrzybek Can anyone take a look? Thank you!

tadayosi commented 7 years ago

retest this please