The Vulnerability History Project
Vulnerabilities
Insights
Curate
Tags
All
Projects
CWEs
Languages
Lessons
Severities
Subsystems
More
News
Projects We Study
How to Contribute
By the Numbers
About Us
Toggle Theme
Warning: Our website does not support Internet Explorer, please use Edge instead.
Introduces more restrictive SMI
by
Randy the Sloth 2016-05-04 07:15:06 UTC
commit 9ac863b339a3513dabd417f4be8a802418a997ba
Struts
Fix
Forced Double OGNL Evaluation CVE-2016-4461
core/src/main/java/com/opensymphony/xwork2/config/entities/ActionConfig.java
+3
-13
core/src/main/java/com/opensymphony/xwork2/config/entities/AllowedMethods.java
+11
-26
core/src/main/java/com/opensymphony/xwork2/config/impl/ActionConfigMatcher.java
-1
core/src/main/java/com/opensymphony/xwork2/config/providers/XmlConfigurationProvider.java
-1
core/src/test/java/com/opensymphony/xwork2/config/entities/AllowedMethodsTest.java
+7
-39
expand_less