Is there a Cross-Site Request Forgery (CSRF) protection in JBoss EAP 6?

Solution Verified - Updated -

Environment

Red Hat JBoss Enterprise Application Platform (EAP) 6.0.1, 6.1.0, 6.1.1

Issue

  • Does JSF 2 which is included in EAP 6 provide CSRF protection?

Resolution

JBoss EAP 6.0.1 ships with JSF release 2.1.13, and EAP 6.1.0 and 6.1.1 ship with 2.1.19. These versions already include Cross-Site Request Forgery (CSRF) protection. However, the next version JSF 2.2 will provide additional and stricter protection.

This solution is part of Red Hat’s fast-track publication program, providing a huge library of solutions that Red Hat engineers have created while supporting our customers. To give you the knowledge you need the instant it becomes available, these articles may be presented in a raw and unedited form.

Close

Welcome! Check out the Getting Started with Red Hat page for quick tours and guides for common tasks.