Disabling the HTTP TRACE method in JBoss EAP doesn't appear to work
Issue
- When the jboss-web.deployer option on the connector to stop the trace option is set (
allowTrace="false"), if you telnet to that port with an OPTIONS query, it still lists TRACE as a valid option - An HTTP OPTIONS query shows TRACE even when it is marked as disabled
Environment
- Red Hat JBoss Enterprise Application Platform (EAP)
- 6.x
Subscriber exclusive content
A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.