[ https://issues.apache.org/jira/browse/WW-5353?focusedWorklogId=916168&page=com.atlassian.jira.plugin.system.issuetabpanels:worklog-tabpanel#worklog-916168 ]
ASF GitHub Bot logged work on WW-5353: -------------------------------------- Author: ASF GitHub Bot Created on: 24/Apr/24 12:34 Start Date: 24/Apr/24 12:34 Worklog Time Spent: 10m Work Description: lukaszlenart commented on PR #919: URL: https://github.com/apache/struts/pull/919#issuecomment-2074844610 I can roll a new Milestone release during the weekend Issue Time Tracking ------------------- Worklog Id: (was: 916168) Time Spent: 1h (was: 50m) > Implement stronger security defaults in Struts 7.0 > -------------------------------------------------- > > Key: WW-5353 > URL: https://issues.apache.org/jira/browse/WW-5353 > Project: Struts 2 > Issue Type: Improvement > Reporter: Kusal Kithul-Godage > Priority: Major > Fix For: 7.0.0 > > Time Spent: 1h > Remaining Estimate: 0h > > {{struts.ognl.allowStaticFieldAccess=false}} > {{struts.ognl.excludedNodeTypes=<TBA>}} > {{struts.ognl.expressionMaxLength=150}} > {{struts.disallowDefaultPackageAccess=true}} > {{struts.disallowProxyMemberAccess=true}} > {{struts.parameters.requireAnnotations=true}} > {{struts.ognl.disallowCustomOgnlMap=true}} > {{struts.allowlist.enable=true}} -- This message was sent by Atlassian Jira (v8.20.10#820010)