Update UncaughtServletException.qhelp

There is no single word in https://cwe.mitre.org/data/definitions/600.html about possible DoS or unexpected state.
This commit is contained in:
Jaroslav Lobačevski
2021-05-03 15:06:57 +03:00
committed by GitHub
parent bb1cb73675
commit 38bce39baa

View File

@@ -2,7 +2,7 @@
<qhelp>
<overview>
<p>
Even though the request-handling methods of <code>Servlet</code> are declared <code>throws IOException, ServletException</code>, it's a bad idea to let such exceptions be thrown. Failure to catch exceptions in a servlet could leave a system in an unexpected state, possibly resulting in denial-of-service attacks, or could lead to exposure of sensitive information because when a servlet throws an exception, the servlet container typically sends debugging information back to the user. That information could be valuable to an attacker.
Even though the request-handling methods of <code>Servlet</code> are declared <code>throws IOException, ServletException</code>, it's a bad idea to let such exceptions be thrown. Failure to catch exceptions in a servlet could lead to exposure of sensitive information because when a servlet throws an exception, the servlet container typically sends debugging information back to the user. That information could be valuable to an attacker.
</p>
</overview>