From 29808ef9272457f8eb25f140280d0e2833af8cbf Mon Sep 17 00:00:00 2001 From: Leif Åstrand Date: Wed, 10 Dec 2014 10:49:45 +0200 Subject: Prevent HTTP Response splitting in case the server doesn't (#19611) Prevent user-provided input used in the redirect from containing newline characters as the user agent would interpret subsequent parts of the input as additional headers or the actual HTTP payload. At least modern versions of Tomcat and Jetty already protect against this kind of attack by escaping received header values, but that is not necessarily the case for older versions or other servlet engines. See https://www.owasp.org/index.php/HTTP_Response_Splitting for details. Change-Id: If4b9bf5fba953073de49c1ab1cba8e5e6bc8e546 --- server/src/com/vaadin/server/VaadinServlet.java | 2 ++ 1 file changed, 2 insertions(+) (limited to 'server') diff --git a/server/src/com/vaadin/server/VaadinServlet.java b/server/src/com/vaadin/server/VaadinServlet.java index e7799dac67..cd6e4cd7cd 100644 --- a/server/src/com/vaadin/server/VaadinServlet.java +++ b/server/src/com/vaadin/server/VaadinServlet.java @@ -403,6 +403,8 @@ public class VaadinServlet extends HttpServlet implements Constants { location = location + "/" + lastPathParameter; String queryString = request.getQueryString(); if (queryString != null) { + // Prevent HTTP Response splitting in case the server doesn't + queryString = queryString.replaceAll("[\\r\\n]", ""); location += '?' + queryString; } response.sendRedirect(location); -- cgit v1.2.3