How to allow custom AJP request attributes after applying the CVE-2020-1938 AJP File Read/Inclusion Vulnerability fix in JBoss EAP 6.4 Update 23+ or with the Security Patch applied to top of Update 22
Issue
- How to allow custom AJP request attributes after applying the CVE-2020-1938 AJP File Read/Inclusion Vulnerability fix in JBoss EAP 6.4 Update 23+ or with the Security Patch applied to top of Update 22
Environment
Red Hat JBoss Enterprise Application Platform (EAP) 6.4 Update 23+
Red Hat JBoss Enterprise Application Platform (EAP) 6.4 Update 22 plus the CVE-2020-1938 Security Patch
Subscriber exclusive content
A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.