[ https://issues.apache.org/jira/browse/WW-5353?focusedWorklogId=915660&page=com.atlassian.jira.plugin.system.issuetabpanels:worklog-tabpanel#worklog-915660 ]
ASF GitHub Bot logged work on WW-5353: -------------------------------------- Author: ASF GitHub Bot Created on: 20/Apr/24 11:09 Start Date: 20/Apr/24 11:09 Worklog Time Spent: 10m Work Description: kusalk opened a new pull request, #919: URL: https://github.com/apache/struts/pull/919 WW-5353 -- Issue Time Tracking ------------------- Worklog Id: (was: 915660) Remaining Estimate: 0h Time Spent: 10m > Implement stronger security defaults in Struts 7.0 > -------------------------------------------------- > > Key: WW-5353 > URL: https://issues.apache.org/jira/browse/WW-5353 > Project: Struts 2 > Issue Type: Improvement > Reporter: Kusal Kithul-Godage > Priority: Major > Fix For: 7.0.0 > > Time Spent: 10m > Remaining Estimate: 0h > > {{struts.ognl.allowStaticFieldAccess=false}} > {{struts.ognl.excludedNodeTypes=<TBA>}} > {{struts.ognl.expressionMaxLength=150}} > {{struts.disallowDefaultPackageAccess=true}} > {{struts.disallowProxyMemberAccess=true}} > {{struts.parameters.requireAnnotations=true}} > {{struts.ognl.disallowCustomOgnlMap=true}} > {{struts.allowlist.enable=true}} -- This message was sent by Atlassian Jira (v8.20.10#820010)