Is it a security risk to show a path to a file inside WEB-INF java

懵懂的女人 提交于 2019-12-23 21:04:43

问题


Was wondering whether this would be a potential security risk. I have a java servlet web app and at the bottom of every page, I generate a "report page problem" link which includes the original url request as well as the path to the JSP that the request was forwarded to. The thing is the JSP pages are sometimes in the WEB-INF folder. Is this a potential security risk? As I might be showing the contents of WEB-INF?

It might show that the request was forwarded to

/WEB-INF/views/user/ViewUser.jsp for example.

回答1:


You could remove part of the path while printing the path and I do not see why users need to know from which jsp the request was forwarded. Otherwise it is not a very big problem as Servlet containers won't serve any content in WEB-INF. By putting your JSPs there, you prevent anyone from directly accessing a JSP by navigating to it in the browser by name.



来源:https://stackoverflow.com/questions/25625429/is-it-a-security-risk-to-show-a-path-to-a-file-inside-web-inf-java

易学教程内所有资源均来自网络或用户发布的内容,如有违反法律规定的内容欢迎反馈
该文章没有解决你所遇到的问题?点击提问,说说你的问题,让更多的人一起探讨吧!