Karan Kurani created WW-5713:
--------------------------------

             Summary: Fail closed for legacy Tiles OGNL evaluation
                 Key: WW-5713
                 URL: https://issues.apache.org/jira/browse/WW-5713
             Project: Struts 2
          Issue Type: Improvement
          Components: Plugin - Tiles
            Reporter: Karan Kurani


The Struts Tiles plugin registers separate {{S2:}} and legacy {{OGNL:}} 
attribute-expression evaluators.

The {{S2:}} evaluator processes ValueStack expressions through the Struts OGNL 
facilities. The legacy {{OGNL:}} evaluator evaluates against the Tiles 
{{Request}} and does not use the Struts OGNL security controls used by 
{{{}S2:{}}}.

This hardening change keeps {{OGNL:}} registered but makes it fail closed by 
default. Evaluation throws Tiles {{EvaluationException}} with migration 
guidance directing users to {{{}S2:{}}}.

Applications that temporarily require the existing raw behavior may explicitly 
set:

{{struts.tiles.ognl.legacy.enabled=true}}

The compatibility flag defaults to {{false}} and is targeted for removal in 
Struts 8.0.0.

The raw evaluator and its global {{OgnlRuntime}} {{Request}} property-accessor 
setup are constructed only when legacy mode is explicitly enabled. This avoids 
mutating the shared OGNL runtime for applications using the secure default.

When legacy mode is enabled, the existing raw behavior is preserved and a clear 
startup migration warning is emitted.

{{{}S2:{}}}, {{{}I18N:{}}}, and {{EL:}} remain unchanged.

Tests cover:
 * default fail-closed behavior;

 * exact migration guidance;

 * non-evaluation of expression markers;

 * construction gating;

 * absence of global accessor initialization under the default;

 * explicit legacy compatibility behavior;

 * startup warning behavior; and

 * real servlet-backed {{S2:}} evaluation.

This is defense-in-depth hardening. No attacker-controlled expression source or 
concrete vulnerability impact has been demonstrated, and no security advisory 
is proposed.



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to