[ https://issues.apache.org/jira/browse/WW-4171?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=13731834#comment-13731834 ]
Lukasz Lenart commented on WW-4171: ----------------------------------- I'm not convinced - only incoming data should be sanitised, ie. in {{ParametersInterceptor}} but this can also be problematic as user can expect what he posts is what he gets :\ I would rather add some warning to the logs or throw an exception if method annotated with {{@SanitizingRequired}} received call with unsanitized value - the developer can add the value to exception list or so. > getText methods are not documented as evaluating OGNL > ----------------------------------------------------- > > Key: WW-4171 > URL: https://issues.apache.org/jira/browse/WW-4171 > Project: Struts 2 > Issue Type: Improvement > Components: Documentation > Affects Versions: 2.3.15.1 > Reporter: Coverity Security Research Laboratory > Assignee: Lukasz Lenart > Priority: Minor > Labels: security > Fix For: 2.3.16 > > > The methods below evaluate OGNL as their first parameter. However they are > not documented as evaluating OGNL. We have observed this occurring in one > project and are contacting the affected vendors. > com.opensymphony.xwork2.TextProviderSupport.getText(String, String[]) > com.opensymphony.xwork2.TextProviderSupport.getText(String, List<?>) > com.opensymphony.xwork2.TextProviderSupport.getText(String) > These methods are then used by ActionSupport (via its getText methods). None > of these methods are documented as evaluating OGNL either. > This issue is recommending that all of these methods are documented as > evaluating OGNL since this may come as a surprise to some developers. -- This message is automatically generated by JIRA. If you think it was sent incorrectly, please contact your JIRA administrators For more information on JIRA, see: http://www.atlassian.com/software/jira