mirror of
https://github.com/apache/struts.git
synced 2026-08-06 07:06:58 +00:00
Merge branch 'hotfix/2.3.16.2'
Conflicts: apps/blank/pom.xml apps/jboss-blank/pom.xml apps/mailreader/pom.xml apps/pom.xml apps/portlet/pom.xml apps/rest-showcase/pom.xml apps/showcase/pom.xml archetypes/pom.xml archetypes/struts2-archetype-angularjs/pom.xml archetypes/struts2-archetype-blank/pom.xml archetypes/struts2-archetype-convention/pom.xml archetypes/struts2-archetype-dbportlet/pom.xml archetypes/struts2-archetype-plugin/pom.xml archetypes/struts2-archetype-portlet/pom.xml archetypes/struts2-archetype-starter/pom.xml assembly/pom.xml bundles/admin/pom.xml bundles/demo/pom.xml bundles/pom.xml core/pom.xml core/src/main/resources/struts-default.xml plugins/cdi/pom.xml plugins/codebehind/pom.xml plugins/config-browser/pom.xml plugins/convention/pom.xml plugins/dojo/pom.xml plugins/dwr/pom.xml plugins/embeddedjsp/pom.xml plugins/gxp/pom.xml plugins/jasperreports/pom.xml plugins/javatemplates/pom.xml plugins/jfreechart/pom.xml plugins/jsf/pom.xml plugins/json/pom.xml plugins/junit/pom.xml plugins/osgi/pom.xml plugins/oval/pom.xml plugins/pell-multipart/pom.xml plugins/plexus/pom.xml plugins/pom.xml plugins/portlet-tiles/pom.xml plugins/portlet/pom.xml plugins/rest/pom.xml plugins/sitegraph/pom.xml plugins/sitemesh/pom.xml plugins/spring/pom.xml plugins/struts1/pom.xml plugins/testng/pom.xml plugins/tiles/pom.xml plugins/tiles3/pom.xml pom.xml xwork-core/pom.xml
This commit is contained in:
+1
-1
@@ -26,7 +26,7 @@
|
||||
<parent>
|
||||
<groupId>org.apache.struts</groupId>
|
||||
<artifactId>struts2-apps</artifactId>
|
||||
<version>2.3.18-SNAPSHOT</version>
|
||||
<version>2.3.16.2</version>
|
||||
</parent>
|
||||
|
||||
<artifactId>struts2-blank</artifactId>
|
||||
|
||||
@@ -26,7 +26,7 @@
|
||||
<parent>
|
||||
<groupId>org.apache.struts</groupId>
|
||||
<artifactId>struts2-apps</artifactId>
|
||||
<version>2.3.18-SNAPSHOT</version>
|
||||
<version>2.3.16.2</version>
|
||||
</parent>
|
||||
|
||||
<artifactId>struts2-jboss-blank</artifactId>
|
||||
|
||||
@@ -26,7 +26,7 @@
|
||||
<parent>
|
||||
<groupId>org.apache.struts</groupId>
|
||||
<artifactId>struts2-apps</artifactId>
|
||||
<version>2.3.18-SNAPSHOT</version>
|
||||
<version>2.3.16.2</version>
|
||||
</parent>
|
||||
|
||||
<artifactId>struts2-mailreader</artifactId>
|
||||
|
||||
+1
-1
@@ -26,7 +26,7 @@
|
||||
<parent>
|
||||
<groupId>org.apache.struts</groupId>
|
||||
<artifactId>struts2-parent</artifactId>
|
||||
<version>2.3.18-SNAPSHOT</version>
|
||||
<version>2.3.16.2</version>
|
||||
</parent>
|
||||
<artifactId>struts2-apps</artifactId>
|
||||
<packaging>pom</packaging>
|
||||
|
||||
@@ -26,7 +26,7 @@
|
||||
<parent>
|
||||
<groupId>org.apache.struts</groupId>
|
||||
<artifactId>struts2-apps</artifactId>
|
||||
<version>2.3.18-SNAPSHOT</version>
|
||||
<version>2.3.16.2</version>
|
||||
</parent>
|
||||
|
||||
<artifactId>struts2-portlet</artifactId>
|
||||
|
||||
@@ -26,12 +26,12 @@
|
||||
<parent>
|
||||
<groupId>org.apache.struts</groupId>
|
||||
<artifactId>struts2-apps</artifactId>
|
||||
<version>2.3.18-SNAPSHOT</version>
|
||||
<version>2.3.16.2</version>
|
||||
</parent>
|
||||
|
||||
<artifactId>struts2-rest-showcase</artifactId>
|
||||
<packaging>war</packaging>
|
||||
<version>2.3.18-SNAPSHOT</version>
|
||||
<version>2.3.16.2</version>
|
||||
<name>Struts 2 Rest Showcase Webapp</name>
|
||||
<description>Struts 2 Rest Showcase Example</description>
|
||||
|
||||
|
||||
@@ -26,7 +26,7 @@
|
||||
<parent>
|
||||
<groupId>org.apache.struts</groupId>
|
||||
<artifactId>struts2-apps</artifactId>
|
||||
<version>2.3.18-SNAPSHOT</version>
|
||||
<version>2.3.16.2</version>
|
||||
</parent>
|
||||
|
||||
<artifactId>struts2-showcase</artifactId>
|
||||
|
||||
+1
-1
@@ -26,7 +26,7 @@
|
||||
<parent>
|
||||
<groupId>org.apache.struts</groupId>
|
||||
<artifactId>struts2-parent</artifactId>
|
||||
<version>2.3.18-SNAPSHOT</version>
|
||||
<version>2.3.16.2</version>
|
||||
</parent>
|
||||
|
||||
<artifactId>struts2-archetypes</artifactId>
|
||||
|
||||
@@ -2,7 +2,7 @@
|
||||
<parent>
|
||||
<groupId>org.apache.struts</groupId>
|
||||
<artifactId>struts2-archetypes</artifactId>
|
||||
<version>2.3.18-SNAPSHOT</version>
|
||||
<version>2.3.16.2</version>
|
||||
</parent>
|
||||
|
||||
<modelVersion>4.0.0</modelVersion>
|
||||
|
||||
@@ -3,7 +3,7 @@
|
||||
<parent>
|
||||
<groupId>org.apache.struts</groupId>
|
||||
<artifactId>struts2-archetypes</artifactId>
|
||||
<version>2.3.18-SNAPSHOT</version>
|
||||
<version>2.3.16.2</version>
|
||||
</parent>
|
||||
|
||||
<modelVersion>4.0.0</modelVersion>
|
||||
|
||||
@@ -2,7 +2,7 @@
|
||||
<parent>
|
||||
<groupId>org.apache.struts</groupId>
|
||||
<artifactId>struts2-archetypes</artifactId>
|
||||
<version>2.3.18-SNAPSHOT</version>
|
||||
<version>2.3.16.2</version>
|
||||
</parent>
|
||||
|
||||
<modelVersion>4.0.0</modelVersion>
|
||||
|
||||
@@ -2,7 +2,7 @@
|
||||
<parent>
|
||||
<groupId>org.apache.struts</groupId>
|
||||
<artifactId>struts2-archetypes</artifactId>
|
||||
<version>2.3.18-SNAPSHOT</version>
|
||||
<version>2.3.16.2</version>
|
||||
</parent>
|
||||
|
||||
<modelVersion>4.0.0</modelVersion>
|
||||
|
||||
@@ -2,7 +2,7 @@
|
||||
<parent>
|
||||
<groupId>org.apache.struts</groupId>
|
||||
<artifactId>struts2-archetypes</artifactId>
|
||||
<version>2.3.18-SNAPSHOT</version>
|
||||
<version>2.3.16.2</version>
|
||||
</parent>
|
||||
|
||||
<modelVersion>4.0.0</modelVersion>
|
||||
|
||||
@@ -2,7 +2,7 @@
|
||||
<parent>
|
||||
<groupId>org.apache.struts</groupId>
|
||||
<artifactId>struts2-archetypes</artifactId>
|
||||
<version>2.3.18-SNAPSHOT</version>
|
||||
<version>2.3.16.2</version>
|
||||
</parent>
|
||||
|
||||
<modelVersion>4.0.0</modelVersion>
|
||||
|
||||
@@ -4,7 +4,7 @@
|
||||
<parent>
|
||||
<groupId>org.apache.struts</groupId>
|
||||
<artifactId>struts2-archetypes</artifactId>
|
||||
<version>2.3.18-SNAPSHOT</version>
|
||||
<version>2.3.16.2</version>
|
||||
</parent>
|
||||
|
||||
<modelVersion>4.0.0</modelVersion>
|
||||
|
||||
+1
-1
@@ -3,7 +3,7 @@
|
||||
<parent>
|
||||
<groupId>org.apache.struts</groupId>
|
||||
<artifactId>struts2-parent</artifactId>
|
||||
<version>2.3.18-SNAPSHOT</version>
|
||||
<version>2.3.16.2</version>
|
||||
</parent>
|
||||
|
||||
<artifactId>struts2-assembly</artifactId>
|
||||
|
||||
@@ -4,7 +4,7 @@
|
||||
<parent>
|
||||
<groupId>org.apache.struts</groupId>
|
||||
<artifactId>struts2-osgi-bundles</artifactId>
|
||||
<version>2.3.18-SNAPSHOT</version>
|
||||
<version>2.3.16.2</version>
|
||||
</parent>
|
||||
|
||||
<artifactId>struts2-osgi-admin-bundle</artifactId>
|
||||
|
||||
@@ -4,7 +4,7 @@
|
||||
<parent>
|
||||
<groupId>org.apache.struts</groupId>
|
||||
<artifactId>struts2-osgi-bundles</artifactId>
|
||||
<version>2.3.18-SNAPSHOT</version>
|
||||
<version>2.3.16.2</version>
|
||||
</parent>
|
||||
|
||||
<artifactId>struts2-osgi-demo-bundle</artifactId>
|
||||
|
||||
+1
-1
@@ -26,7 +26,7 @@
|
||||
<parent>
|
||||
<groupId>org.apache.struts</groupId>
|
||||
<artifactId>struts2-parent</artifactId>
|
||||
<version>2.3.18-SNAPSHOT</version>
|
||||
<version>2.3.16.2</version>
|
||||
</parent>
|
||||
|
||||
<artifactId>struts2-osgi-bundles</artifactId>
|
||||
|
||||
+1
-1
@@ -26,7 +26,7 @@
|
||||
<parent>
|
||||
<groupId>org.apache.struts</groupId>
|
||||
<artifactId>struts2-parent</artifactId>
|
||||
<version>2.3.18-SNAPSHOT</version>
|
||||
<version>2.3.16.2</version>
|
||||
</parent>
|
||||
<artifactId>struts2-core</artifactId>
|
||||
<packaging>jar</packaging>
|
||||
|
||||
@@ -24,6 +24,7 @@ package org.apache.struts2.interceptor;
|
||||
import com.opensymphony.xwork2.ActionContext;
|
||||
import com.opensymphony.xwork2.ActionInvocation;
|
||||
import com.opensymphony.xwork2.interceptor.AbstractInterceptor;
|
||||
import com.opensymphony.xwork2.ExcludedPatterns;
|
||||
import com.opensymphony.xwork2.util.TextParseUtil;
|
||||
import com.opensymphony.xwork2.util.ValueStack;
|
||||
import com.opensymphony.xwork2.util.logging.Logger;
|
||||
@@ -173,7 +174,8 @@ public class CookieInterceptor extends AbstractInterceptor {
|
||||
private Set<String> cookiesValueSet = Collections.emptySet();
|
||||
|
||||
// Allowed names of cookies
|
||||
private Pattern acceptedPattern = Pattern.compile(ACCEPTED_PATTERN);
|
||||
private Pattern acceptedPattern = Pattern.compile(ACCEPTED_PATTERN, Pattern.CASE_INSENSITIVE);
|
||||
private Pattern excludedPattern = Pattern.compile(ExcludedPatterns.CLASS_ACCESS_PATTERN, Pattern.CASE_INSENSITIVE);
|
||||
|
||||
/**
|
||||
* Set the <code>cookiesName</code> which if matched will allow the cookie
|
||||
@@ -223,7 +225,7 @@ public class CookieInterceptor extends AbstractInterceptor {
|
||||
String name = cookie.getName();
|
||||
String value = cookie.getValue();
|
||||
|
||||
if (acceptedPattern.matcher(name).matches()) {
|
||||
if (isAcceptableName(name) && isAcceptableValue(value)) {
|
||||
if (cookiesNameSet.contains("*")) {
|
||||
if (LOG.isDebugEnabled()) {
|
||||
LOG.debug("contains cookie name [*] in configured cookies name set, cookie with name [" + name + "] with value [" + value + "] will be injected");
|
||||
@@ -233,7 +235,7 @@ public class CookieInterceptor extends AbstractInterceptor {
|
||||
populateCookieValueIntoStack(name, value, cookiesMap, stack);
|
||||
}
|
||||
} else {
|
||||
LOG.warn("Cookie name [" + name + "] does not match accepted cookie names pattern [" + acceptedPattern + "]");
|
||||
LOG.warn("Cookie name [#0] with value [#1] was rejected!", name, value);
|
||||
}
|
||||
}
|
||||
}
|
||||
@@ -244,6 +246,72 @@ public class CookieInterceptor extends AbstractInterceptor {
|
||||
return invocation.invoke();
|
||||
}
|
||||
|
||||
/**
|
||||
* Checks if value of Cookie doesn't contain vulnerable code
|
||||
*
|
||||
* @param value of Cookie
|
||||
* @return true|false
|
||||
*/
|
||||
protected boolean isAcceptableValue(String value) {
|
||||
boolean matches = !excludedPattern.matcher(value).matches();
|
||||
if (!matches) {
|
||||
if (LOG.isTraceEnabled()) {
|
||||
LOG.trace("Cookie value [#0] matches excludedPattern [#1]", value, ExcludedPatterns.CLASS_ACCESS_PATTERN);
|
||||
}
|
||||
}
|
||||
return matches;
|
||||
}
|
||||
|
||||
/**
|
||||
* Checks if name of Cookie doesn't contain vulnerable code
|
||||
*
|
||||
* @param name of Cookie
|
||||
* @return true|false
|
||||
*/
|
||||
protected boolean isAcceptableName(String name) {
|
||||
return !isExcluded(name) && isAccepted(name);
|
||||
}
|
||||
|
||||
/**
|
||||
* Checks if name of Cookie match {@link #acceptedPattern}
|
||||
*
|
||||
* @param name of Cookie
|
||||
* @return true|false
|
||||
*/
|
||||
protected boolean isAccepted(String name) {
|
||||
boolean matches = acceptedPattern.matcher(name).matches();
|
||||
if (matches) {
|
||||
if (LOG.isTraceEnabled()) {
|
||||
LOG.trace("Cookie [#0] matches acceptedPattern [#1]", name, ACCEPTED_PATTERN);
|
||||
}
|
||||
} else {
|
||||
if (LOG.isTraceEnabled()) {
|
||||
LOG.trace("Cookie [#0] doesn't match acceptedPattern [#1]", name, ACCEPTED_PATTERN);
|
||||
}
|
||||
}
|
||||
return matches;
|
||||
}
|
||||
|
||||
/**
|
||||
* Checks if name of Cookie match {@link #excludedPattern}
|
||||
*
|
||||
* @param name of Cookie
|
||||
* @return true|false
|
||||
*/
|
||||
protected boolean isExcluded(String name) {
|
||||
boolean matches = excludedPattern.matcher(name).matches();
|
||||
if (matches) {
|
||||
if (LOG.isTraceEnabled()) {
|
||||
LOG.trace("Cookie [#0] matches excludedPattern [#1]", name, ExcludedPatterns.CLASS_ACCESS_PATTERN);
|
||||
}
|
||||
} else {
|
||||
if (LOG.isTraceEnabled()) {
|
||||
LOG.trace("Cookie [#0] doesn't match excludedPattern [#1]", name, ExcludedPatterns.CLASS_ACCESS_PATTERN);
|
||||
}
|
||||
}
|
||||
return matches;
|
||||
}
|
||||
|
||||
/**
|
||||
* Hook that populate cookie value into value stack (hence the action)
|
||||
* if the criteria is satisfied (if the cookie value matches with those configured).
|
||||
|
||||
@@ -203,7 +203,7 @@
|
||||
<interceptor-ref name="multiselect"/>
|
||||
<interceptor-ref name="actionMappingParams"/>
|
||||
<interceptor-ref name="params">
|
||||
<param name="excludeParams">(.*\.|^)class\..*,^dojo\..*,^struts\..*,^session\..*,^request\..*,^application\..*,^servlet(Request|Response)\..*,^parameters\..*,^action:.*,^method:.*</param>
|
||||
<param name="excludeParams">^action:.*,^method:.*</param>
|
||||
</interceptor-ref>
|
||||
<interceptor-ref name="conversionError"/>
|
||||
<interceptor-ref name="deprecation"/>
|
||||
@@ -260,7 +260,7 @@
|
||||
<interceptor-ref name="datetime"/>
|
||||
<interceptor-ref name="multiselect"/>
|
||||
<interceptor-ref name="params">
|
||||
<param name="excludeParams">(.*\.|^)class\..*,^dojo\..*,^struts\..*,^session\..*,^request\..*,^application\..*,^servlet(Request|Response)\..*,^parameters\..*,^action:.*,^method:.*</param>
|
||||
<param name="excludeParams">^action:.*,^method:.*</param>
|
||||
</interceptor-ref>
|
||||
<interceptor-ref name="servletConfig"/>
|
||||
<interceptor-ref name="prepare"/>
|
||||
@@ -270,7 +270,7 @@
|
||||
<interceptor-ref name="staticParams"/>
|
||||
<interceptor-ref name="actionMappingParams"/>
|
||||
<interceptor-ref name="params">
|
||||
<param name="excludeParams">(.*\.|^)class\..*,^dojo\..*,^struts\..*,^session\..*,^request\..*,^application\..*,^servlet(Request|Response)\..*,^parameters\..*,^action:.*,^method:.*</param>
|
||||
<param name="excludeParams">^action:.*,^method:.*</param>
|
||||
</interceptor-ref>
|
||||
<interceptor-ref name="conversionError"/>
|
||||
<interceptor-ref name="validation">
|
||||
@@ -308,7 +308,7 @@
|
||||
<interceptor-ref name="staticParams"/>
|
||||
<interceptor-ref name="actionMappingParams"/>
|
||||
<interceptor-ref name="params">
|
||||
<param name="excludeParams">(.*\.|^)class\..*,^dojo\..*,^struts\..*,^session\..*,^request\..*,^application\..*,^servlet(Request|Response)\..*,^parameters\..*,^action:.*,^method:.*</param>
|
||||
<param name="excludeParams">^action:.*,^method:.*</param>
|
||||
</interceptor-ref>
|
||||
<interceptor-ref name="conversionError"/>
|
||||
<interceptor-ref name="validation">
|
||||
|
||||
@@ -22,10 +22,12 @@
|
||||
package org.apache.struts2.interceptor;
|
||||
|
||||
import java.util.Collections;
|
||||
import java.util.HashMap;
|
||||
import java.util.Map;
|
||||
|
||||
import javax.servlet.http.Cookie;
|
||||
|
||||
import com.opensymphony.xwork2.mock.MockActionInvocation;
|
||||
import org.easymock.MockControl;
|
||||
import org.springframework.mock.web.MockHttpServletRequest;
|
||||
|
||||
@@ -316,6 +318,70 @@ public class CookieInterceptorTest extends StrutsInternalTestCase {
|
||||
assertEquals(ActionContext.getContext().getValueStack().findValue("cookie3"), null);
|
||||
}
|
||||
|
||||
public void testCookiesWithClassPollution() throws Exception {
|
||||
MockHttpServletRequest request = new MockHttpServletRequest();
|
||||
String pollution1 = "model['class']['classLoader']['jarPath']";
|
||||
String pollution2 = "model.class.classLoader.jarPath";
|
||||
String pollution3 = "class.classLoader.jarPath";
|
||||
String pollution4 = "class['classLoader']['jarPath']";
|
||||
String pollution5 = "model[\"class\"]['classLoader']['jarPath']";
|
||||
String pollution6 = "class[\"classLoader\"]['jarPath']";
|
||||
|
||||
request.setCookies(
|
||||
new Cookie(pollution1, "pollution1"),
|
||||
new Cookie("pollution1", pollution1),
|
||||
new Cookie(pollution2, "pollution2"),
|
||||
new Cookie("pollution2", pollution2),
|
||||
new Cookie(pollution3, "pollution3"),
|
||||
new Cookie("pollution3", pollution3),
|
||||
new Cookie(pollution4, "pollution4"),
|
||||
new Cookie("pollution4", pollution4),
|
||||
new Cookie(pollution5, "pollution5"),
|
||||
new Cookie("pollution5", pollution5),
|
||||
new Cookie(pollution6, "pollution6"),
|
||||
new Cookie("pollution6", pollution6)
|
||||
);
|
||||
ServletActionContext.setRequest(request);
|
||||
|
||||
final Map<String, Boolean> excludedName = new HashMap<String, Boolean>();
|
||||
final Map<String, Boolean> excludedValue = new HashMap<String, Boolean>();
|
||||
|
||||
CookieInterceptor interceptor = new CookieInterceptor() {
|
||||
@Override
|
||||
protected boolean isAcceptableName(String name) {
|
||||
boolean accepted = super.isAcceptableName(name);
|
||||
excludedName.put(name, accepted);
|
||||
return accepted;
|
||||
}
|
||||
|
||||
@Override
|
||||
protected boolean isAcceptableValue(String value) {
|
||||
boolean accepted = super.isAcceptableValue(value);
|
||||
excludedValue.put(value, accepted);
|
||||
return accepted;
|
||||
}
|
||||
};
|
||||
interceptor.setCookiesName("*");
|
||||
|
||||
MockActionInvocation invocation = new MockActionInvocation();
|
||||
invocation.setAction(new MockActionWithCookieAware());
|
||||
|
||||
interceptor.intercept(invocation);
|
||||
|
||||
assertFalse(excludedName.get(pollution1));
|
||||
assertFalse(excludedName.get(pollution2));
|
||||
assertFalse(excludedName.get(pollution3));
|
||||
assertFalse(excludedName.get(pollution4));
|
||||
assertFalse(excludedName.get(pollution5));
|
||||
assertFalse(excludedName.get(pollution6));
|
||||
|
||||
assertFalse(excludedValue.get(pollution1));
|
||||
assertFalse(excludedValue.get(pollution2));
|
||||
assertFalse(excludedValue.get(pollution3));
|
||||
assertFalse(excludedValue.get(pollution4));
|
||||
assertFalse(excludedValue.get(pollution5));
|
||||
assertFalse(excludedValue.get(pollution6));
|
||||
}
|
||||
|
||||
public static class MockActionWithCookieAware extends ActionSupport implements CookiesAware {
|
||||
|
||||
|
||||
+1
-1
@@ -25,7 +25,7 @@
|
||||
<parent>
|
||||
<groupId>org.apache.struts</groupId>
|
||||
<artifactId>struts2-plugins</artifactId>
|
||||
<version>2.3.18-SNAPSHOT</version>
|
||||
<version>2.3.16.2</version>
|
||||
</parent>
|
||||
|
||||
<artifactId>struts2-cdi-plugin</artifactId>
|
||||
|
||||
@@ -26,7 +26,7 @@
|
||||
<parent>
|
||||
<groupId>org.apache.struts</groupId>
|
||||
<artifactId>struts2-plugins</artifactId>
|
||||
<version>2.3.18-SNAPSHOT</version>
|
||||
<version>2.3.16.2</version>
|
||||
</parent>
|
||||
|
||||
<artifactId>struts2-codebehind-plugin</artifactId>
|
||||
|
||||
@@ -26,7 +26,7 @@
|
||||
<parent>
|
||||
<groupId>org.apache.struts</groupId>
|
||||
<artifactId>struts2-plugins</artifactId>
|
||||
<version>2.3.18-SNAPSHOT</version>
|
||||
<version>2.3.16.2</version>
|
||||
</parent>
|
||||
|
||||
<artifactId>struts2-config-browser-plugin</artifactId>
|
||||
|
||||
@@ -3,7 +3,7 @@
|
||||
<parent>
|
||||
<groupId>org.apache.struts</groupId>
|
||||
<artifactId>struts2-plugins</artifactId>
|
||||
<version>2.3.18-SNAPSHOT</version>
|
||||
<version>2.3.16.2</version>
|
||||
</parent>
|
||||
|
||||
<artifactId>struts2-convention-plugin</artifactId>
|
||||
|
||||
@@ -25,7 +25,7 @@
|
||||
<parent>
|
||||
<artifactId>struts2-plugins</artifactId>
|
||||
<groupId>org.apache.struts</groupId>
|
||||
<version>2.3.18-SNAPSHOT</version>
|
||||
<version>2.3.16.2</version>
|
||||
</parent>
|
||||
|
||||
<modelVersion>4.0.0</modelVersion>
|
||||
|
||||
+1
-1
@@ -26,7 +26,7 @@
|
||||
<parent>
|
||||
<groupId>org.apache.struts</groupId>
|
||||
<artifactId>struts2-plugins</artifactId>
|
||||
<version>2.3.18-SNAPSHOT</version>
|
||||
<version>2.3.16.2</version>
|
||||
</parent>
|
||||
|
||||
<artifactId>struts2-dwr-plugin</artifactId>
|
||||
|
||||
@@ -26,7 +26,7 @@
|
||||
<parent>
|
||||
<groupId>org.apache.struts</groupId>
|
||||
<artifactId>struts2-plugins</artifactId>
|
||||
<version>2.3.18-SNAPSHOT</version>
|
||||
<version>2.3.16.2</version>
|
||||
</parent>
|
||||
|
||||
<artifactId>struts2-embeddedjsp-plugin</artifactId>
|
||||
|
||||
+1
-1
@@ -3,7 +3,7 @@
|
||||
<parent>
|
||||
<groupId>org.apache.struts</groupId>
|
||||
<artifactId>struts2-plugins</artifactId>
|
||||
<version>2.3.18-SNAPSHOT</version>
|
||||
<version>2.3.16.2</version>
|
||||
</parent>
|
||||
|
||||
<artifactId>struts2-gxp-plugin</artifactId>
|
||||
|
||||
@@ -26,7 +26,7 @@
|
||||
<parent>
|
||||
<groupId>org.apache.struts</groupId>
|
||||
<artifactId>struts2-plugins</artifactId>
|
||||
<version>2.3.18-SNAPSHOT</version>
|
||||
<version>2.3.16.2</version>
|
||||
</parent>
|
||||
|
||||
<artifactId>struts2-jasperreports-plugin</artifactId>
|
||||
|
||||
@@ -25,7 +25,7 @@
|
||||
<parent>
|
||||
<groupId>org.apache.struts</groupId>
|
||||
<artifactId>struts2-plugins</artifactId>
|
||||
<version>2.3.18-SNAPSHOT</version>
|
||||
<version>2.3.16.2</version>
|
||||
</parent>
|
||||
|
||||
<artifactId>struts2-javatemplates-plugin</artifactId>
|
||||
|
||||
@@ -26,7 +26,7 @@
|
||||
<parent>
|
||||
<groupId>org.apache.struts</groupId>
|
||||
<artifactId>struts2-plugins</artifactId>
|
||||
<version>2.3.18-SNAPSHOT</version>
|
||||
<version>2.3.16.2</version>
|
||||
</parent>
|
||||
|
||||
<artifactId>struts2-jfreechart-plugin</artifactId>
|
||||
|
||||
+1
-1
@@ -26,7 +26,7 @@
|
||||
<parent>
|
||||
<groupId>org.apache.struts</groupId>
|
||||
<artifactId>struts2-plugins</artifactId>
|
||||
<version>2.3.18-SNAPSHOT</version>
|
||||
<version>2.3.16.2</version>
|
||||
</parent>
|
||||
|
||||
<artifactId>struts2-jsf-plugin</artifactId>
|
||||
|
||||
@@ -26,7 +26,7 @@
|
||||
<parent>
|
||||
<groupId>org.apache.struts</groupId>
|
||||
<artifactId>struts2-plugins</artifactId>
|
||||
<version>2.3.18-SNAPSHOT</version>
|
||||
<version>2.3.16.2</version>
|
||||
</parent>
|
||||
|
||||
<artifactId>struts2-json-plugin</artifactId>
|
||||
|
||||
@@ -26,7 +26,7 @@
|
||||
<parent>
|
||||
<groupId>org.apache.struts</groupId>
|
||||
<artifactId>struts2-plugins</artifactId>
|
||||
<version>2.3.18-SNAPSHOT</version>
|
||||
<version>2.3.16.2</version>
|
||||
</parent>
|
||||
|
||||
<artifactId>struts2-junit-plugin</artifactId>
|
||||
|
||||
@@ -4,7 +4,7 @@
|
||||
<parent>
|
||||
<groupId>org.apache.struts</groupId>
|
||||
<artifactId>struts2-plugins</artifactId>
|
||||
<version>2.3.18-SNAPSHOT</version>
|
||||
<version>2.3.16.2</version>
|
||||
</parent>
|
||||
|
||||
<artifactId>struts2-osgi-plugin</artifactId>
|
||||
|
||||
@@ -26,7 +26,7 @@
|
||||
<parent>
|
||||
<groupId>org.apache.struts</groupId>
|
||||
<artifactId>struts2-plugins</artifactId>
|
||||
<version>2.3.18-SNAPSHOT</version>
|
||||
<version>2.3.16.2</version>
|
||||
</parent>
|
||||
|
||||
<artifactId>struts2-oval-plugin</artifactId>
|
||||
|
||||
@@ -26,7 +26,7 @@
|
||||
<parent>
|
||||
<groupId>org.apache.struts</groupId>
|
||||
<artifactId>struts2-plugins</artifactId>
|
||||
<version>2.3.18-SNAPSHOT</version>
|
||||
<version>2.3.16.2</version>
|
||||
</parent>
|
||||
|
||||
<artifactId>struts2-pell-multipart-plugin</artifactId>
|
||||
|
||||
@@ -26,7 +26,7 @@
|
||||
<parent>
|
||||
<groupId>org.apache.struts</groupId>
|
||||
<artifactId>struts2-plugins</artifactId>
|
||||
<version>2.3.18-SNAPSHOT</version>
|
||||
<version>2.3.16.2</version>
|
||||
</parent>
|
||||
|
||||
<artifactId>struts2-plexus-plugin</artifactId>
|
||||
|
||||
+1
-1
@@ -26,7 +26,7 @@
|
||||
<parent>
|
||||
<groupId>org.apache.struts</groupId>
|
||||
<artifactId>struts2-parent</artifactId>
|
||||
<version>2.3.18-SNAPSHOT</version>
|
||||
<version>2.3.16.2</version>
|
||||
</parent>
|
||||
|
||||
<artifactId>struts2-plugins</artifactId>
|
||||
|
||||
@@ -26,7 +26,7 @@
|
||||
<parent>
|
||||
<groupId>org.apache.struts</groupId>
|
||||
<artifactId>struts2-plugins</artifactId>
|
||||
<version>2.3.18-SNAPSHOT</version>
|
||||
<version>2.3.16.2</version>
|
||||
</parent>
|
||||
|
||||
<artifactId>struts2-portlet-tiles-plugin</artifactId>
|
||||
|
||||
@@ -3,7 +3,7 @@
|
||||
<parent>
|
||||
<groupId>org.apache.struts</groupId>
|
||||
<artifactId>struts2-plugins</artifactId>
|
||||
<version>2.3.18-SNAPSHOT</version>
|
||||
<version>2.3.16.2</version>
|
||||
</parent>
|
||||
|
||||
<artifactId>struts2-portlet-plugin</artifactId>
|
||||
|
||||
@@ -26,11 +26,11 @@
|
||||
<parent>
|
||||
<groupId>org.apache.struts</groupId>
|
||||
<artifactId>struts2-plugins</artifactId>
|
||||
<version>2.3.18-SNAPSHOT</version>
|
||||
<version>2.3.16.2</version>
|
||||
</parent>
|
||||
|
||||
<artifactId>struts2-rest-plugin</artifactId>
|
||||
<version>2.3.18-SNAPSHOT</version>
|
||||
<version>2.3.16.2</version>
|
||||
<name>Struts 2 REST Plugin</name>
|
||||
|
||||
<properties>
|
||||
|
||||
@@ -26,7 +26,7 @@
|
||||
<parent>
|
||||
<groupId>org.apache.struts</groupId>
|
||||
<artifactId>struts2-plugins</artifactId>
|
||||
<version>2.3.18-SNAPSHOT</version>
|
||||
<version>2.3.16.2</version>
|
||||
</parent>
|
||||
|
||||
<artifactId>struts2-sitegraph-plugin</artifactId>
|
||||
|
||||
@@ -26,7 +26,7 @@
|
||||
<parent>
|
||||
<groupId>org.apache.struts</groupId>
|
||||
<artifactId>struts2-plugins</artifactId>
|
||||
<version>2.3.18-SNAPSHOT</version>
|
||||
<version>2.3.16.2</version>
|
||||
</parent>
|
||||
|
||||
<artifactId>struts2-sitemesh-plugin</artifactId>
|
||||
|
||||
@@ -26,7 +26,7 @@
|
||||
<parent>
|
||||
<groupId>org.apache.struts</groupId>
|
||||
<artifactId>struts2-plugins</artifactId>
|
||||
<version>2.3.18-SNAPSHOT</version>
|
||||
<version>2.3.16.2</version>
|
||||
</parent>
|
||||
|
||||
<artifactId>struts2-spring-plugin</artifactId>
|
||||
|
||||
@@ -26,7 +26,7 @@
|
||||
<parent>
|
||||
<groupId>org.apache.struts</groupId>
|
||||
<artifactId>struts2-plugins</artifactId>
|
||||
<version>2.3.18-SNAPSHOT</version>
|
||||
<version>2.3.16.2</version>
|
||||
</parent>
|
||||
|
||||
<artifactId>struts2-struts1-plugin</artifactId>
|
||||
|
||||
@@ -26,7 +26,7 @@
|
||||
<parent>
|
||||
<groupId>org.apache.struts</groupId>
|
||||
<artifactId>struts2-plugins</artifactId>
|
||||
<version>2.3.18-SNAPSHOT</version>
|
||||
<version>2.3.16.2</version>
|
||||
</parent>
|
||||
|
||||
<artifactId>struts2-testng-plugin</artifactId>
|
||||
|
||||
@@ -26,7 +26,7 @@
|
||||
<parent>
|
||||
<groupId>org.apache.struts</groupId>
|
||||
<artifactId>struts2-plugins</artifactId>
|
||||
<version>2.3.18-SNAPSHOT</version>
|
||||
<version>2.3.16.2</version>
|
||||
</parent>
|
||||
|
||||
<artifactId>struts2-tiles-plugin</artifactId>
|
||||
|
||||
@@ -26,7 +26,7 @@
|
||||
<parent>
|
||||
<groupId>org.apache.struts</groupId>
|
||||
<artifactId>struts2-plugins</artifactId>
|
||||
<version>2.3.18-SNAPSHOT</version>
|
||||
<version>2.3.16.2</version>
|
||||
</parent>
|
||||
|
||||
<artifactId>struts2-tiles3-plugin</artifactId>
|
||||
|
||||
@@ -9,7 +9,7 @@
|
||||
|
||||
<modelVersion>4.0.0</modelVersion>
|
||||
<artifactId>struts2-parent</artifactId>
|
||||
<version>2.3.18-SNAPSHOT</version>
|
||||
<version>2.3.16.2</version>
|
||||
<packaging>pom</packaging>
|
||||
<name>Struts 2</name>
|
||||
<url>http://struts.apache.org/</url>
|
||||
@@ -31,8 +31,7 @@
|
||||
<connection>scm:git:git://git.apache.org/struts.git</connection>
|
||||
<developerConnection>scm:git:https://git-wip-us.apache.org/repos/asf/struts.git</developerConnection>
|
||||
<url>http://git.apache.org/struts.git</url>
|
||||
<tag>HEAD</tag>
|
||||
</scm>
|
||||
</scm>
|
||||
|
||||
<issueManagement>
|
||||
<system>JIRA</system>
|
||||
|
||||
@@ -7,42 +7,42 @@
|
||||
<archetype>
|
||||
<groupId>org.apache.struts</groupId>
|
||||
<artifactId>struts2-archetype-blank</artifactId>
|
||||
<version>2.3.16.1</version>
|
||||
<version>2.3.16.2</version>
|
||||
<repository>http://repo1.maven.org/maven2/</repository>
|
||||
<description>Struts 2 Archetypes - Blank</description>
|
||||
</archetype>
|
||||
<archetype>
|
||||
<groupId>org.apache.struts</groupId>
|
||||
<artifactId>struts2-archetype-convention</artifactId>
|
||||
<version>2.3.16.1</version>
|
||||
<version>2.3.16.2</version>
|
||||
<repository>http://repo1.maven.org/maven2/</repository>
|
||||
<description>Struts 2 Archetypes - Blank Convention</description>
|
||||
</archetype>
|
||||
<archetype>
|
||||
<groupId>org.apache.struts</groupId>
|
||||
<artifactId>struts2-archetype-dbportlet</artifactId>
|
||||
<version>2.3.16.1</version>
|
||||
<version>2.3.16.2</version>
|
||||
<repository>http://repo1.maven.org/maven2/</repository>
|
||||
<description>Struts 2 Archetypes - Database Portlet</description>
|
||||
</archetype>
|
||||
<archetype>
|
||||
<groupId>org.apache.struts</groupId>
|
||||
<artifactId>struts2-archetype-plugin</artifactId>
|
||||
<version>2.3.16.1</version>
|
||||
<version>2.3.16.2</version>
|
||||
<repository>http://repo1.maven.org/maven2/</repository>
|
||||
<description>Struts 2 Archetypes - Plugin</description>
|
||||
</archetype>
|
||||
<archetype>
|
||||
<groupId>org.apache.struts</groupId>
|
||||
<artifactId>struts2-archetype-portlet</artifactId>
|
||||
<version>2.3.16.1</version>
|
||||
<version>2.3.16.2</version>
|
||||
<repository>http://repo1.maven.org/maven2/</repository>
|
||||
<description>Struts 2 Archetypes - Portlet</description>
|
||||
</archetype>
|
||||
<archetype>
|
||||
<groupId>org.apache.struts</groupId>
|
||||
<artifactId>struts2-archetype-starter</artifactId>
|
||||
<version>2.3.16.1</version>
|
||||
<version>2.3.16.2</version>
|
||||
<repository>http://repo1.maven.org/maven2/</repository>
|
||||
<description>Struts 2 Archetypes - Starter</description>
|
||||
</archetype>
|
||||
|
||||
+1
-1
@@ -5,7 +5,7 @@
|
||||
<parent>
|
||||
<groupId>org.apache.struts</groupId>
|
||||
<artifactId>struts2-parent</artifactId>
|
||||
<version>2.3.18-SNAPSHOT</version>
|
||||
<version>2.3.16.2</version>
|
||||
</parent>
|
||||
|
||||
<groupId>org.apache.struts.xwork</groupId>
|
||||
|
||||
@@ -0,0 +1,22 @@
|
||||
package com.opensymphony.xwork2;
|
||||
|
||||
/**
|
||||
* ExcludedPatterns contains hard-coded patterns that must be rejected by {@link com.opensymphony.xwork2.interceptor.ParametersInterceptor}
|
||||
* and partially in CookInterceptor
|
||||
*/
|
||||
public class ExcludedPatterns {
|
||||
|
||||
public static final String CLASS_ACCESS_PATTERN = "(.*\\.|^|.*|\\[('|\"))class(\\.|('|\")]|\\[).*";
|
||||
|
||||
public static final String[] EXCLUDED_PATTERNS = {
|
||||
CLASS_ACCESS_PATTERN,
|
||||
"^dojo\\..*",
|
||||
"^struts\\..*",
|
||||
"^session\\..*",
|
||||
"^request\\..*",
|
||||
"^application\\..*",
|
||||
"^servlet(Request|Response)\\..*",
|
||||
"^parameters\\..*"
|
||||
};
|
||||
|
||||
}
|
||||
+15
-4
@@ -17,6 +17,7 @@ package com.opensymphony.xwork2.interceptor;
|
||||
|
||||
import com.opensymphony.xwork2.ActionContext;
|
||||
import com.opensymphony.xwork2.ActionInvocation;
|
||||
import com.opensymphony.xwork2.ExcludedPatterns;
|
||||
import com.opensymphony.xwork2.ValidationAware;
|
||||
import com.opensymphony.xwork2.XWorkConstants;
|
||||
import com.opensymphony.xwork2.conversion.impl.InstantiatingNullHandler;
|
||||
@@ -148,16 +149,20 @@ public class ParametersInterceptor extends MethodFilterInterceptor {
|
||||
private int paramNameMaxLength = PARAM_NAME_MAX_LENGTH;
|
||||
|
||||
protected boolean ordered = false;
|
||||
protected Set<Pattern> excludeParams = Collections.emptySet();
|
||||
protected Set<Pattern> excludeParams;
|
||||
protected Set<Pattern> acceptParams = Collections.emptySet();
|
||||
|
||||
private boolean devMode = false;
|
||||
|
||||
// Allowed names of parameters
|
||||
private Pattern acceptedPattern = Pattern.compile(ACCEPTED_PARAM_NAMES);
|
||||
private Pattern acceptedPattern = Pattern.compile(ACCEPTED_PARAM_NAMES, Pattern.CASE_INSENSITIVE);
|
||||
|
||||
private ValueStackFactory valueStackFactory;
|
||||
|
||||
public ParametersInterceptor() {
|
||||
initializeHardCodedExcludePatterns();
|
||||
}
|
||||
|
||||
@Inject
|
||||
public void setValueStackFactory(ValueStackFactory valueStackFactory) {
|
||||
this.valueStackFactory = valueStackFactory;
|
||||
@@ -486,6 +491,13 @@ public class ParametersInterceptor extends MethodFilterInterceptor {
|
||||
return excludeParams;
|
||||
}
|
||||
|
||||
protected void initializeHardCodedExcludePatterns() {
|
||||
excludeParams = new HashSet<Pattern>();
|
||||
for (String pattern : ExcludedPatterns.EXCLUDED_PATTERNS) {
|
||||
excludeParams.add(Pattern.compile(pattern, Pattern.CASE_INSENSITIVE));
|
||||
}
|
||||
}
|
||||
|
||||
/**
|
||||
* Sets a comma-delimited list of regular expressions to match
|
||||
* parameters that should be removed from the parameter map.
|
||||
@@ -495,9 +507,8 @@ public class ParametersInterceptor extends MethodFilterInterceptor {
|
||||
public void setExcludeParams(String commaDelim) {
|
||||
Collection<String> excludePatterns = ArrayUtils.asCollection(commaDelim);
|
||||
if (excludePatterns != null) {
|
||||
excludeParams = new HashSet<Pattern>();
|
||||
for (String pattern : excludePatterns) {
|
||||
excludeParams.add(Pattern.compile(pattern));
|
||||
excludeParams.add(Pattern.compile(pattern, Pattern.CASE_INSENSITIVE));
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
+64
@@ -18,6 +18,7 @@ package com.opensymphony.xwork2.interceptor;
|
||||
import com.opensymphony.xwork2.Action;
|
||||
import com.opensymphony.xwork2.ActionContext;
|
||||
import com.opensymphony.xwork2.ActionProxy;
|
||||
import com.opensymphony.xwork2.ExcludedPatterns;
|
||||
import com.opensymphony.xwork2.ModelDrivenAction;
|
||||
import com.opensymphony.xwork2.SimpleAction;
|
||||
import com.opensymphony.xwork2.TestBean;
|
||||
@@ -44,10 +45,12 @@ import java.util.ArrayList;
|
||||
import java.util.Collection;
|
||||
import java.util.Collections;
|
||||
import java.util.HashMap;
|
||||
import java.util.HashSet;
|
||||
import java.util.LinkedHashMap;
|
||||
import java.util.LinkedList;
|
||||
import java.util.List;
|
||||
import java.util.Map;
|
||||
import java.util.regex.Pattern;
|
||||
|
||||
|
||||
/**
|
||||
@@ -268,6 +271,62 @@ public class ParametersInterceptorTest extends XWorkTestCase {
|
||||
assertNull(session.get("user5"));
|
||||
}
|
||||
|
||||
public void testArrayClassPollutionBlockedByPattern() throws Exception {
|
||||
// given
|
||||
final String pollution1 = "model.class.classLoader.jarPath";
|
||||
final String pollution2 = "model['class']['classLoader']['jarPath']";
|
||||
final String pollution3 = "model[\"class\"]['classLoader']['jarPath']";
|
||||
final String pollution4 = "class.classLoader.jarPath";
|
||||
final String pollution5 = "class['classLoader']['jarPath']";
|
||||
final String pollution6 = "class[\"classLoader\"]['jarPath']";
|
||||
|
||||
loadConfigurationProviders(new XWorkConfigurationProvider(), new XmlConfigurationProvider("xwork-param-test.xml"));
|
||||
final Map<String, Object> params = new HashMap<String, Object>() {
|
||||
{
|
||||
put(pollution1, "bad");
|
||||
put(pollution2, "bad");
|
||||
put(pollution3, "bad");
|
||||
put(pollution4, "bad");
|
||||
put(pollution5, "bad");
|
||||
put(pollution6, "bad");
|
||||
}
|
||||
};
|
||||
|
||||
final Map<String, Boolean> excluded = new HashMap<String, Boolean>();
|
||||
ParametersInterceptor pi = new ParametersInterceptor() {
|
||||
|
||||
@Override
|
||||
protected void initializeHardCodedExcludePatterns() {
|
||||
this.excludeParams = new HashSet<Pattern>();
|
||||
}
|
||||
|
||||
@Override
|
||||
protected boolean isExcluded(String paramName) {
|
||||
boolean result = super.isExcluded(paramName);
|
||||
excluded.put(paramName, result);
|
||||
return result;
|
||||
}
|
||||
|
||||
};
|
||||
|
||||
pi.setExcludeParams("(.*\\.|^|.*|\\[('|\"))class(\\.|('|\")]|\\[).*");
|
||||
container.inject(pi);
|
||||
ValueStack vs = ActionContext.getContext().getValueStack();
|
||||
|
||||
// when
|
||||
ValidateAction action = new ValidateAction();
|
||||
pi.setParameters(action, vs, params);
|
||||
|
||||
// then
|
||||
assertEquals(0, action.getActionMessages().size());
|
||||
assertTrue(excluded.get(pollution1));
|
||||
assertTrue(excluded.get(pollution2));
|
||||
assertTrue(excluded.get(pollution3));
|
||||
assertTrue(excluded.get(pollution4));
|
||||
assertTrue(excluded.get(pollution5));
|
||||
assertTrue(excluded.get(pollution6));
|
||||
}
|
||||
|
||||
public void testAccessToOgnlInternals() throws Exception {
|
||||
// given
|
||||
Map<String, Object> params = new HashMap<String, Object>();
|
||||
@@ -668,6 +727,11 @@ public class ParametersInterceptorTest extends XWorkTestCase {
|
||||
assertEquals(expected, actual);
|
||||
}
|
||||
|
||||
public void testExcludedPatternsGetInitialized() throws Exception {
|
||||
ParametersInterceptor parametersInterceptor = new ParametersInterceptor();
|
||||
assertEquals(ExcludedPatterns.EXCLUDED_PATTERNS.length, parametersInterceptor.excludeParams.size());
|
||||
}
|
||||
|
||||
private ValueStack injectValueStack(Map<String, Object> actual) {
|
||||
ValueStack stack = createStubValueStack(actual);
|
||||
container.inject(stack);
|
||||
|
||||
Reference in New Issue
Block a user