This is an automated email from the ASF dual-hosted git repository. rmaucher pushed a commit to branch 11.0.x in repository https://gitbox.apache.org/repos/asf/tomcat.git
commit 44bd8a99e1fa61a18755b09ec9e0eceec864f22d Author: opencode <[email protected]> AuthorDate: Wed Sep 30 16:24:53 2026 +0200 Use an instanceof check when instantiating the configured randomClass in CsrfPreventionFilterBase.init() so a class that is not a Random subclass produces the intended ServletException rather than a raw ClassCastException --- java/org/apache/catalina/filters/CsrfPreventionFilterBase.java | 7 ++++++- 1 file changed, 6 insertions(+), 1 deletion(-) diff --git a/java/org/apache/catalina/filters/CsrfPreventionFilterBase.java b/java/org/apache/catalina/filters/CsrfPreventionFilterBase.java index 15d2e00c67..a899aa71da 100644 --- a/java/org/apache/catalina/filters/CsrfPreventionFilterBase.java +++ b/java/org/apache/catalina/filters/CsrfPreventionFilterBase.java @@ -88,7 +88,12 @@ public abstract class CsrfPreventionFilterBase extends FilterBase { try { Class<?> clazz = Class.forName(randomClass); - randomSource = (Random) clazz.getConstructor().newInstance(); + Object instance = clazz.getConstructor().newInstance(); + if (instance instanceof Random random) { + randomSource = random; + } else { + throw new ServletException(sm.getString("csrfPrevention.invalidRandomClass", randomClass)); + } } catch (ReflectiveOperationException e) { throw new ServletException(sm.getString("csrfPrevention.invalidRandomClass", randomClass), e); } --------------------------------------------------------------------- To unsubscribe, e-mail: [email protected] For additional commands, e-mail: [email protected]
