Author: alexoree
Date: Thu May 18 23:33:38 2017
New Revision: 1795571

URL: http://svn.apache.org/viewvc?rev=1795571&view=rev
Log:
adding jUDDI security page

Modified:
    juddi/cms-site/trunk/content/security.mdtext

Modified: juddi/cms-site/trunk/content/security.mdtext
URL: 
http://svn.apache.org/viewvc/juddi/cms-site/trunk/content/security.mdtext?rev=1795571&r1=1795570&r2=1795571&view=diff
==============================================================================
--- juddi/cms-site/trunk/content/security.mdtext (original)
+++ juddi/cms-site/trunk/content/security.mdtext Thu May 18 23:33:38 2017
@@ -6,9 +6,9 @@ Title: Security Advisories
 
 VERSION: 3.1.2, 3.1.3, 3.1.4, and 3.1.5 utilize the portlets based user 
interface also known as 'Pluto', 'jUDDI Portal', 'UDDI Portal' or 'uddi-console'
 
-PROBLEMTYPE:Open Redirect
+PROBLEMTYPE: Open Redirect
 
-REFERENCES:https://lists.apache.org/thread.html/d0e00f2e147a9e9b13a6829133092f349b2882bf6860397368a52600@%3Cannounce.tomcat.apache.org%3E
+REFERENCES: http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2015-5241
 
 DESCRIPTION: After logging into the portal, the logout jsp page redirects the 
browser back to the login page after. It is feasible for malicious user to 
redirect the browser to an unintended web page. User session data, credentials, 
and auth tokens are cleared before the redirect.
 



---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to