Description
There is a potential XXS attack in the HttpTunnelServlet where we return the clientId header directly in an error. The fix is just to avoid sending the header back at all, as I didn't want to add an additional dependency to encode it.
Attachments
Issue Links
- links to