Details
-
Bug
-
Status: Closed
-
Major
-
Resolution: Fixed
-
Servlets Get 2.1.40
-
None
Description
The JsonRenderServlet recursion selector is supposed to be:
"-1" | "infinity" | [0-9]+
Following SLING-2324, a value > Integer.MAX_VALUE is considered to be "infinity".
However, we don't enforce that the value is not a negative number (besides the allowed "-1") nor do we prevent it from being a numeric which is not real numbers (i.e., not matching [0-9]+).
We should make sure we only accept: "-1" | "infinity" | [0-9]+
Attachments
Issue Links
- Blocked
-
SLING-10591 Non latin characters can be used as recursion level in JsonRenderer
- Resolved
- is related to
-
SLING-10591 Non latin characters can be used as recursion level in JsonRenderer
- Resolved