[GitHub] [commons-lang] chtompki commented on issue #459: (doc): Document public RandomStringUtils exploit

2019-09-18 Thread GitBox
chtompki commented on issue #459: (doc): Document public RandomStringUtils exploit URL: https://github.com/apache/commons-lang/pull/459#issuecomment-532689260 I'm still mildly confused how: https://github.com/apache/commons-lang/blob/commons-lang-3.9/src/main/java/org/apache/commons

[GitHub] [commons-lang] chtompki commented on issue #459: (doc): Document public RandomStringUtils exploit

2019-09-16 Thread GitBox
chtompki commented on issue #459: (doc): Document public RandomStringUtils exploit URL: https://github.com/apache/commons-lang/pull/459#issuecomment-531924375 Did anyone note that in 3.9 we have the following at the top of the JavaDoc for `RandomStringUtils` > Caveat: Instances of R