Author: jfrederic.clere(a)jboss.com
Date: 2011-06-06 08:10:58 -0400 (Mon, 06 Jun 2011)
New Revision: 1732
Modified:
branches/JBOSSWEB_2_0_0_GA_CP/src/share/classes/org/apache/catalina/loader/WebappClassLoader.java
Log:
Fix CVE-2010-1622.
Modified:
branches/JBOSSWEB_2_0_0_GA_CP/src/share/classes/org/apache/catalina/loader/WebappClassLoader.java
===================================================================
---
branches/JBOSSWEB_2_0_0_GA_CP/src/share/classes/org/apache/catalina/loader/WebappClassLoader.java 2011-06-06
12:05:32 UTC (rev 1731)
+++
branches/JBOSSWEB_2_0_0_GA_CP/src/share/classes/org/apache/catalina/loader/WebappClassLoader.java 2011-06-06
12:10:58 UTC (rev 1732)
@@ -1425,7 +1425,7 @@
public URL[] getURLs() {
if (repositoryURLs != null) {
- return repositoryURLs;
+ return repositoryURLs.clone();
}
URL[] external = super.getURLs();
@@ -1454,7 +1454,7 @@
repositoryURLs = new URL[0];
}
- return repositoryURLs;
+ return repositoryURLs.clone();
}
Show replies by date