jmestwa-coder opened a new pull request, #4316:
URL: https://github.com/apache/logging-log4j2/pull/4316

   `DumpTag` (`log:dump`) writes the names and values of every attribute in the 
selected scope straight into the page:
   
   - request- and session-scope attributes are routinely attacker-influenced (a 
request parameter copied into a request attribute, a form bean, etc.), so any 
page using `log:dump` with those scopes emits reflected/stored XSS
   - `doEndTag` concatenated the attribute `name` and `value` into the HTML 
output with no escaping
   - both are now escaped with `StringBuilders.escapeXml` before writing, the 
same escaping `HtmlLayout` and `Log4j1XmlLayout` already apply to event data
   
   ## Checklist
   
   - [x] Base your changes on the `2.x` branch
   - [x] `./mvnw verify` succeeds for the affected module
   - [x] Changelog entry added under `src/changelog/.2.x.x`
   - [x] Tests are provided
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to