Uploaded image for project: 'Gateway'
  1. Gateway
  2. GTWY-697

Stack traces returned through the user interface.

XMLWordPrintable

    • Icon: Defect Defect
    • Resolution: Won't Do
    • Icon: Major Major
    • Recycle Bin
    • 1.0.0-M2
    • Security
    • None

      Stack traces can still be displayed through the user interface. The application should not be returning stack traces as a security measure. Stack traces can be used to glean information about how a hacker may attack a vulnerability in the site.

      This was an important security violation we received on the previous system from the ORNL security scan.

      Currently our global exception handling is dispatched through the Spring mechanism. This should be replaced by a top level web filter to catch all exceptions that come out of our application. This will handle all application generated messages, however Tomcat generated exception may still be visible, this may be handled by overriding Tomcats default error pages. For more information see: NATHAN LINK TO THE PAGE OVERRIDE ISSUE

              wilhelmi Nathan Wilhelmi (Inactive)
              wilhelmi Nathan Wilhelmi (Inactive)
              Votes:
              0 Vote for this issue
              Watchers:
              0 Start watching this issue

                Created:
                Updated:
                Resolved:

                  Estimated:
                  Original Estimate - 30 minutes
                  30m
                  Remaining:
                  Remaining Estimate - 30 minutes
                  30m
                  Logged:
                  Time Spent - Not Specified
                  Not Specified