Description
As reported by Christoph Neuroth at OFBIZ-5254, we still use a patched version from OFBIZ-3135 and it's time to update to last version
Attachments
Attachments
Issue Links
- is duplicated by
-
OFBIZ-5795 Update esapi to 2.1.0
- Closed
- is part of
-
OFBIZ-1525 Issue to group security concerns
- Open
- is related to
-
OFBIZ-5254 Services allow arbitrary HTML for parameters with allow-html set to "safe"
- Closed
-
OFBIZ-3135 In owasp-esapi-java, htmlCodec.decode is broken for all entities where entity.substr(0, x) exists
- Closed