This is an automated email from the ASF dual-hosted git repository.

rmaucher pushed a commit to branch 9.0.x
in repository https://gitbox.apache.org/repos/asf/tomcat.git

commit a3c0bc010bb8a17750dd251024c3a8be7632c882
Author: opencode <[email protected]>
AuthorDate: Wed Sep 30 16:24:53 2026 +0200

    Use an instanceof check when instantiating the configured randomClass in 
CsrfPreventionFilterBase.init() so a class that is not a Random subclass 
produces the intended ServletException rather than a raw ClassCastException
---
 java/org/apache/catalina/filters/CsrfPreventionFilterBase.java | 7 ++++++-
 1 file changed, 6 insertions(+), 1 deletion(-)

diff --git a/java/org/apache/catalina/filters/CsrfPreventionFilterBase.java 
b/java/org/apache/catalina/filters/CsrfPreventionFilterBase.java
index e8b7870814..b5abf953da 100644
--- a/java/org/apache/catalina/filters/CsrfPreventionFilterBase.java
+++ b/java/org/apache/catalina/filters/CsrfPreventionFilterBase.java
@@ -88,7 +88,12 @@ public abstract class CsrfPreventionFilterBase extends 
FilterBase {
 
         try {
             Class<?> clazz = Class.forName(randomClass);
-            randomSource = (Random) clazz.getConstructor().newInstance();
+            Object instance = clazz.getConstructor().newInstance();
+            if (instance instanceof Random random) {
+                randomSource = random;
+            } else {
+                throw new 
ServletException(sm.getString("csrfPrevention.invalidRandomClass", 
randomClass));
+            }
         } catch (ReflectiveOperationException e) {
             throw new 
ServletException(sm.getString("csrfPrevention.invalidRandomClass", 
randomClass), e);
         }


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to