Issue: |
|
---|---|
Date: |
|
Severity: | Medium |
Requires Admin Access: | No |
Fix Version: | 23.06+, LTS 22.03.7+, LTS 23.01.4+ |
Credit: | Internal Security Team |
Description: |
In dotCMS, the NormalizationFilter is run on every request to strip invalid characters from incoming URLs. The default list of invalid characters to strip failed to include double slashes ( Affected dotCMS versions:
|
Mitigation: |
URLs that contain double slashes can be blocked at an upstream firewall / WAF or can be blocked by using dotCMS config variables. In dotCMS, the default list of invalid characters can be overridden by passing an environmental variable It is also possible to pass an environmental variable
|
References |
|