Karan Kurani created WW-5713:
--------------------------------
Summary: Fail closed for legacy Tiles OGNL evaluation
Key: WW-5713
URL: https://issues.apache.org/jira/browse/WW-5713
Project: Struts 2
Issue Type: Improvement
Components: Plugin - Tiles
Reporter: Karan Kurani
The Struts Tiles plugin registers separate {{S2:}} and legacy {{OGNL:}}
attribute-expression evaluators.
The {{S2:}} evaluator processes ValueStack expressions through the Struts OGNL
facilities. The legacy {{OGNL:}} evaluator evaluates against the Tiles
{{Request}} and does not use the Struts OGNL security controls used by
{{{}S2:{}}}.
This hardening change keeps {{OGNL:}} registered but makes it fail closed by
default. Evaluation throws Tiles {{EvaluationException}} with migration
guidance directing users to {{{}S2:{}}}.
Applications that temporarily require the existing raw behavior may explicitly
set:
{{struts.tiles.ognl.legacy.enabled=true}}
The compatibility flag defaults to {{false}} and is targeted for removal in
Struts 8.0.0.
The raw evaluator and its global {{OgnlRuntime}} {{Request}} property-accessor
setup are constructed only when legacy mode is explicitly enabled. This avoids
mutating the shared OGNL runtime for applications using the secure default.
When legacy mode is enabled, the existing raw behavior is preserved and a clear
startup migration warning is emitted.
{{{}S2:{}}}, {{{}I18N:{}}}, and {{EL:}} remain unchanged.
Tests cover:
* default fail-closed behavior;
* exact migration guidance;
* non-evaluation of expression markers;
* construction gating;
* absence of global accessor initialization under the default;
* explicit legacy compatibility behavior;
* startup warning behavior; and
* real servlet-backed {{S2:}} evaluation.
This is defense-in-depth hardening. No attacker-controlled expression source or
concrete vulnerability impact has been demonstrated, and no security advisory
is proposed.
--
This message was sent by Atlassian Jira
(v8.20.10#820010)