Emmanuel Lécharny created DIRAPI-441:
----------------------------------------
Summary: Malformed base64 in DSML document throws uncaught
IllegalArgumentException
Key: DIRAPI-441
URL: https://issues.apache.org/jira/browse/DIRAPI-441
Project: Directory Client API
Issue Type: Bug
Affects Versions: 2.1.8
Reporter: Emmanuel Lécharny
Fix For: 2.1.9
A remote user submits a _batchRequest_ with _<value
xsi:type="xsd:base64Binary">!!!not-base64!!!</value>_
_Base64.decode_ throws _IllegalArgumentException_ past all handlers,
_processDSML_ throws, no _batchResponse_ is written, and repeating the request
cheaply kills every processing thread/request. A hostile server's *DSML*
responses crash client-side consumers the same way.
--
This message was sent by Atlassian Jira
(v8.20.10#820010)
---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]