The company I work for has an application that allows users to view files (PDF's etc). There is a bug in it that our security audit discovered that allows someone to enter something like ../../datasource-ds.xml and view the contents of the config files.
This is being fixed by our developers, but I'd like to make sure that the vulnerability doesn't exist in some other way. How can I lock down the conf and deploy directories so that no one else can do this? I'm still relatively new to JBoss and could use some help locking things down.
Would putting an .htaccess file in the conf and deploy directories be enough to keep people out of them without impacting application functionality?
Any suggestions would be appreciated.