Details
-
Improvement
-
Status: Closed
-
Major
-
Resolution: Fixed
-
JCR Webdav 2.2.0, JCR DavEx 1.2.0
-
None
Description
The WebDAV functionality in Jackrabbit has improved since the 2.4.4 version currently included in the o.a.s.jcr.webdav bundle. Most notably JCR-3630 fixes an XSS issue that is still present in 2.4.4.
It would thus be a good idea to upgrade the jackrabbit-jcr-server dependency to 2.4.5 (to get the JCR-3630 fix) or to 2.6.4 (for JCR-3630 and other fixes/improvements).
Attachments
Issue Links
- is related to
-
JCR-3630 XSS in DirListingExportHandler
- Closed