[ https://issues.apache.org/jira/browse/WW-4146?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=14045831#comment-14045831 ]
ASF subversion and git services commented on WW-4146: ----------------------------------------------------- Commit 63de7730ee2be146e90227ed067ed108f4a2a534 in struts's branch refs/heads/feature/WW-4295-localization from [~lukaszlenart] [ https://git-wip-us.apache.org/repos/asf?p=struts.git;h=63de773 ] WW-4146 caches only valid OGNL expressions, closes #12 > cache attack at OgnlUtil.expressions > ------------------------------------- > > Key: WW-4146 > URL: https://issues.apache.org/jira/browse/WW-4146 > Project: Struts 2 > Issue Type: Bug > Components: Expression Language > Affects Versions: 2.3.15.1 > Reporter: bruce liu > Assignee: Lukasz Lenart > Fix For: 2.3.18 > > Attachments: WW-4146.patch > > > in class com.opensymphony.xwork2.ognl.OgnlUtil, code : > {code:java} > tree = expressions.get(expression); > if (tree == null) { > tree = Ognl.parseExpression(expression); > expressions.putIfAbsent(expression, tree); > } > {code} > every parameter in the request cached in field expressions which is an > instances of ConcurrentMap<String, Object>, use parameterName as key. so i > construct huge different parameters that has different name (like "abc[123], > abc[124]" ), they all cached in expressions, this cause outofmemory error, > and let map acted like a list . -- This message was sent by Atlassian JIRA (v6.2#6252)