Source Code Disclosure - /WEB-INF Folder
- Risk:
High
- Type:
- Active
- CWE:
- CWE-541
- Summary
Java source code was disclosed by the web server in Java class files in the WEB-INF folder. The class files can be dis-assembled to produce source code which very closely matches the original source code.
- Solution
The web server should be configured to not serve the /WEB-INF folder or its contents to web browsers, since it contains sensitive information such as compiled Java source code and properties files which may contain credentials. Java classes deployed with the application should be obfuscated, as an additional layer of defence in a "defence-in-depth" approach.
- Other info
- class A { }
AWS outage crashes Amazon, PrimeVideo, Fortnite, Perplexity and more
MSS Claims NSA Used 42 Cyber Tools in Multi-Stage Attack on Beijing Time Systems
TikTok videos continue to push infostealers in ClickFix attacks
Experian fined $3.2 million for mass-collecting personal data
Europol Dismantles SIM Farm Network Powering 49 Million Fake Accounts Worldwide
Google ads for fake Homebrew, LogMeIn sites push infostealers
New .NET CAPI Backdoor Targets Russian Auto and E-Commerce Firms via Phishing ZIPs
Silver Fox Expands Winos 4.0 Attacks to Japan and Malaysia via HoldingHands RAT
CVE-2025-59230 Microsoft Windows Improper Access Control Vulnerability
CVE-2025-6264 Rapid7 Velociraptor Incorrect Default Permissions Vulnerability
CVE-2016-7836 SKYSEA Client View Improper Authentication Vulnerability
CVE-2017-3881 Cisco IOS and IOS XE Remote Code Execution Vulnerability
CVE-2021-43226 Microsoft Windows Privilege Escalation Vulnerability
CVE-2025-47827 IGEL OS Use of a Key Past its Expiration Date Vulnerability
CVE-2007-0671 Microsoft Office Excel Remote Code Execution Vulnerability
CVE-2010-3765 Mozilla Multiple Products Remote Code Execution Vulnerability
CVE-2018-7600 Drupal Core Remote Code Execution Vulnerability
InformationalInformation Disclosure - Suspicious Comments
InformationalRe-examine Cache-control Directives
InformationalModern Web Application
CWE-1098 Data Element containing Pointer Item without Proper Copy Control Element
CWE-1233 Security-Sensitive Hardware Controls with Missing Lock Bit Protection
CWE-406 Insufficient Control of Network Message Volume (Network Amplification)
CWE-943 Improper Neutralization of Special Elements in Data Query Logic
Free online web security scanner