[ https://issues.apache.org/jira/browse/WW-4146?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=14034986#comment-14034986 ]
ASF GitHub Bot commented on WW-4146: ------------------------------------ Github user lukaszlenart commented on a diff in the pull request: https://github.com/apache/struts/pull/12#discussion_r13902929 --- Diff: xwork-core/src/main/java/com/opensymphony/xwork2/ognl/OgnlUtil.java --- @@ -279,7 +279,8 @@ public Object compile(String expression) throws OgnlException { if (tree == null) { tree = Ognl.parseExpression(expression); checkEnableEvalExpression(tree, context); - expressions.putIfAbsent(expression, tree); +// duplicated cache put +// expressions.putIfAbsent(expression, tree); --- End diff -- Remove the code, not comment it out > cache attack at OgnlUtil.expressions > ------------------------------------- > > Key: WW-4146 > URL: https://issues.apache.org/jira/browse/WW-4146 > Project: Struts 2 > Issue Type: Bug > Components: Expression Language > Affects Versions: 2.3.15.1 > Reporter: bruce liu > Assignee: Lukasz Lenart > Fix For: 2.3.18 > > Attachments: WW-4146.patch > > > in class com.opensymphony.xwork2.ognl.OgnlUtil, code : > {code:java} > tree = expressions.get(expression); > if (tree == null) { > tree = Ognl.parseExpression(expression); > expressions.putIfAbsent(expression, tree); > } > {code} > every parameter in the request cached in field expressions which is an > instances of ConcurrentMap<String, Object>, use parameterName as key. so i > construct huge different parameters that has different name (like "abc[123], > abc[124]" ), they all cached in expressions, this cause outofmemory error, > and let map acted like a list . -- This message was sent by Atlassian JIRA (v6.2#6252)