Hi,
the following page describes a workaround for CVE-2019-11581:
https://confluence.atlassian.com/jira/jira-security-advisory-2019-07-10-973486595.html
"Block the /secure/admin/SendBulkMail!default.jspa..."
/secure/admin/SendBulkMail!default.jspa..."
But I can't find this file - under the path ".../secure/admin/..." i only find the file "default.jsp".
But I can't find this file -
When I go deeper into the directory there is the file "sendbulkmail.jsp" but the path of this file is "\secure\admin\views\mail".
Which is the document which I have to block for this workaround?
Thank you in advance!
Stefan
Hey @[deleted]
If you're running a reverse proxy (apache/nginx etc) you can look to block the /secure/admin/SendBulkMail!default.jspa URL at the proxy level.
CCM
Hey @Craig Castle-Mead
thank you for your answer. But I want to block the file on Tomcat directly.
Like in the following link which is on the workaround page.
https://confluence.atlassian.com/kb/how-to-block-access-to-a-specific-url-at-tomcat-966668691.html
Do you know which of these files is the right one to block?
Thank you for your help.
Hi Stefan,
You will need to edit server.xml file ($application-install/conf/server.xml file) & add the above condition per the KB link you shared. You don't need to go & block any file at server level.
$application-install/conf/server.xml
Hope it is clear.
Hi @Anurag Jalan
this is clear but I'm not sure which file / file path I have to write into "/path/to/file/to/block" in the server.xml.
<Context path="/path/to/file/to/block" docBase="" > <Valapp className="org.apache.catalina.valapps.RemoteAddrValapp" deny="*" /> </Context>
The described file "SendBulkMail!default.jspa" is not available under the path ".../secure/admin/...".
I only have the file "default.jsp" under the path ".../secure/admin/..." and the file "sendbulkmail.jsp" under the path "\secure\admin\views\mail".
Is one of these files the right one to write into the server.xml?
Thank you!
It looks like you're new here. Sign in or register to get started.