[jira] [Updated] (OFBIZ-11306) POC for CSRF Token (CVE-2019-0235)

2020-04-06 Thread Jacques Le Roux (Jira)
[ https://issues.apache.org/jira/browse/OFBIZ-11306?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Jacques Le Roux updated OFBIZ-11306: Summary: POC for CSRF Token (CVE-2019-0235) (was: POC for CSRF Token (CVE-2019-12425))

[jira] [Updated] (OFBIZ-11306) POC for CSRF Token (CVE-2019-12425)

2020-04-05 Thread Jacques Le Roux (Jira)
[ https://issues.apache.org/jira/browse/OFBIZ-11306?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Jacques Le Roux updated OFBIZ-11306: Summary: POC for CSRF Token (CVE-2019-12425) (was: POC for CSRF Token) > POC for CSRF

[jira] [Updated] (OFBIZ-11306) POC for CSRF Token

2020-03-09 Thread Jacques Le Roux (Jira)
[ https://issues.apache.org/jira/browse/OFBIZ-11306?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Jacques Le Roux updated OFBIZ-11306: Description: CRSF tokens are generated using SecureRandom class (maybe later a JWT with a

[jira] [Updated] (OFBIZ-11306) POC for CSRF Token

2020-02-26 Thread Jacques Le Roux (Jira)
[ https://issues.apache.org/jira/browse/OFBIZ-11306?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Jacques Le Roux updated OFBIZ-11306: Attachment: OFBIZ-11306-alternative merged with James's.patch > POC for CSRF Token >

[jira] [Updated] (OFBIZ-11306) POC for CSRF Token

2020-02-26 Thread Jacques Le Roux (Jira)
[ https://issues.apache.org/jira/browse/OFBIZ-11306?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Jacques Le Roux updated OFBIZ-11306: Attachment: OFBIZ-11306_Plugins.patch > POC for CSRF Token > -- > >

[jira] [Updated] (OFBIZ-11306) POC for CSRF Token

2020-02-25 Thread Jacques Le Roux (Jira)
[ https://issues.apache.org/jira/browse/OFBIZ-11306?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Jacques Le Roux updated OFBIZ-11306: Attachment: OFBIZ-11306-alternative merged with James's.patch > POC for CSRF Token >

[jira] [Updated] (OFBIZ-11306) POC for CSRF Token

2020-02-25 Thread Jacques Le Roux (Jira)
[ https://issues.apache.org/jira/browse/OFBIZ-11306?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Jacques Le Roux updated OFBIZ-11306: Attachment: OFBIZ-11306-alternative merged with James's.patch > POC for CSRF Token >

[jira] [Updated] (OFBIZ-11306) POC for CSRF Token

2020-02-23 Thread James Yong (Jira)
[ https://issues.apache.org/jira/browse/OFBIZ-11306?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] James Yong updated OFBIZ-11306: --- Attachment: OFBIZ-11306-alternative.patch > POC for CSRF Token > -- > >

[jira] [Updated] (OFBIZ-11306) POC for CSRF Token

2020-02-20 Thread Jacques Le Roux (Jira)
[ https://issues.apache.org/jira/browse/OFBIZ-11306?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Jacques Le Roux updated OFBIZ-11306: Description: CRSF tokens are generated using SecureRandom class (maybe later a JWT with a

[jira] [Updated] (OFBIZ-11306) POC for CSRF Token

2020-02-20 Thread Jacques Le Roux (Jira)
[ https://issues.apache.org/jira/browse/OFBIZ-11306?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Jacques Le Roux updated OFBIZ-11306: Attachment: partyTokenMap.webtools.txt > POC for CSRF Token > -- > >

[jira] [Updated] (OFBIZ-11306) POC for CSRF Token

2020-02-19 Thread James Yong (Jira)
[ https://issues.apache.org/jira/browse/OFBIZ-11306?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] James Yong updated OFBIZ-11306: --- Attachment: OFBIZ-11306-alternative.patch > POC for CSRF Token > -- > >

[jira] [Updated] (OFBIZ-11306) POC for CSRF Token

2020-02-18 Thread James Yong (Jira)
[ https://issues.apache.org/jira/browse/OFBIZ-11306?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] James Yong updated OFBIZ-11306: --- Attachment: OFBIZ-11306-alternative.patch > POC for CSRF Token > -- > >

[jira] [Updated] (OFBIZ-11306) POC for CSRF Token

2020-02-16 Thread James Yong (Jira)
[ https://issues.apache.org/jira/browse/OFBIZ-11306?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] James Yong updated OFBIZ-11306: --- Attachment: OFBIZ-11306-alternative.patch > POC for CSRF Token > -- > >

[jira] [Updated] (OFBIZ-11306) POC for CSRF Token

2020-02-15 Thread James Yong (Jira)
[ https://issues.apache.org/jira/browse/OFBIZ-11306?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] James Yong updated OFBIZ-11306: --- Attachment: OFBIZ-11306-alternative.patch > POC for CSRF Token > -- > >

[jira] [Updated] (OFBIZ-11306) POC for CSRF Token

2020-02-14 Thread Jacques Le Roux (Jira)
[ https://issues.apache.org/jira/browse/OFBIZ-11306?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Jacques Le Roux updated OFBIZ-11306: Attachment: OFBIZ-11306-alternative.patch > POC for CSRF Token > -- > >

[jira] [Updated] (OFBIZ-11306) POC for CSRF Token

2020-02-12 Thread Jacques Le Roux (Jira)
[ https://issues.apache.org/jira/browse/OFBIZ-11306?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Jacques Le Roux updated OFBIZ-11306: Parent: OFBIZ-1525 Issue Type: Sub-task (was: Improvement) > POC for CSRF Token

[jira] [Updated] (OFBIZ-11306) POC for CSRF Token

2020-02-11 Thread Jacques Le Roux (Jira)
[ https://issues.apache.org/jira/browse/OFBIZ-11306?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Jacques Le Roux updated OFBIZ-11306: Attachment: OFBIZ-11306-alternative.patch > POC for CSRF Token > -- > >

[jira] [Updated] (OFBIZ-11306) POC for CSRF Token

2020-02-09 Thread James Yong (Jira)
[ https://issues.apache.org/jira/browse/OFBIZ-11306?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] James Yong updated OFBIZ-11306: --- Attachment: OFBIZ-11306-alternative.patch > POC for CSRF Token > -- > >

[jira] [Updated] (OFBIZ-11306) POC for CSRF Token

2020-02-09 Thread Jacques Le Roux (Jira)
[ https://issues.apache.org/jira/browse/OFBIZ-11306?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Jacques Le Roux updated OFBIZ-11306: Attachment: OFBIZ-11306-alternative.patch > POC for CSRF Token > -- > >

[jira] [Updated] (OFBIZ-11306) POC for CSRF Token

2020-02-08 Thread Jacques Le Roux (Jira)
[ https://issues.apache.org/jira/browse/OFBIZ-11306?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Jacques Le Roux updated OFBIZ-11306: Attachment: OFBIZ-11306.patch > POC for CSRF Token > -- > >

[jira] [Updated] (OFBIZ-11306) POC for CSRF Token

2020-02-07 Thread Jacques Le Roux (Jira)
[ https://issues.apache.org/jira/browse/OFBIZ-11306?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Jacques Le Roux updated OFBIZ-11306: Attachment: OFBIZ-11306.patch > POC for CSRF Token > -- > >

[jira] [Updated] (OFBIZ-11306) POC for CSRF Token

2020-02-07 Thread Jacques Le Roux (Jira)
[ https://issues.apache.org/jira/browse/OFBIZ-11306?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Jacques Le Roux updated OFBIZ-11306: Attachment: OFBIZ-11306.patch > POC for CSRF Token > -- > >

[jira] [Updated] (OFBIZ-11306) POC for CSRF Token

2020-02-06 Thread Jacques Le Roux (Jira)
[ https://issues.apache.org/jira/browse/OFBIZ-11306?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Jacques Le Roux updated OFBIZ-11306: Attachment: OFBIZ-11306.patch > POC for CSRF Token > -- > >

[jira] [Updated] (OFBIZ-11306) POC for CSRF Token

2020-01-26 Thread Jacques Le Roux (Jira)
[ https://issues.apache.org/jira/browse/OFBIZ-11306?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Jacques Le Roux updated OFBIZ-11306: Description: CRSF tokens are generated using SecureRandom class (maybe later a JWT with a

[jira] [Updated] (OFBIZ-11306) POC for CSRF Token

2020-01-26 Thread James Yong (Jira)
[ https://issues.apache.org/jira/browse/OFBIZ-11306?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] James Yong updated OFBIZ-11306: --- Description: CRSF tokens are generated using SecureRandom class (maybe later a JWT with a "time

[jira] [Updated] (OFBIZ-11306) POC for CSRF Token

2020-01-26 Thread James Yong (Jira)
[ https://issues.apache.org/jira/browse/OFBIZ-11306?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] James Yong updated OFBIZ-11306: --- Description: CRSF tokens are generated using SecureRandom class (maybe later a JWT with a "time

[jira] [Updated] (OFBIZ-11306) POC for CSRF Token

2020-01-26 Thread James Yong (Jira)
[ https://issues.apache.org/jira/browse/OFBIZ-11306?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] James Yong updated OFBIZ-11306: --- Description: CRSF tokens are generated using SecureRandom class (maybe later a JWT with a "time

[jira] [Updated] (OFBIZ-11306) POC for CSRF Token

2020-01-26 Thread Jacques Le Roux (Jira)
[ https://issues.apache.org/jira/browse/OFBIZ-11306?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Jacques Le Roux updated OFBIZ-11306: Description: CRSF tokens are generated using SecureRandom class (maybe later a JWT with a

[jira] [Updated] (OFBIZ-11306) POC for CSRF Token

2020-01-26 Thread Jacques Le Roux (Jira)
[ https://issues.apache.org/jira/browse/OFBIZ-11306?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Jacques Le Roux updated OFBIZ-11306: Description: CRSF tokens are generated using SecureRandom class (maybe later a JWT with a

[jira] [Updated] (OFBIZ-11306) POC for CSRF Token

2020-01-26 Thread Jacques Le Roux (Jira)
[ https://issues.apache.org/jira/browse/OFBIZ-11306?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Jacques Le Roux updated OFBIZ-11306: Description: CRSF tokens are generated using SecureRandom class (maybe later a JWT with a

[jira] [Updated] (OFBIZ-11306) POC for CSRF Token

2020-01-24 Thread Jacques Le Roux (Jira)
[ https://issues.apache.org/jira/browse/OFBIZ-11306?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Jacques Le Roux updated OFBIZ-11306: Attachment: CsrfTokenTransform.java CsrfTokenAjaxTransform.java

[jira] [Updated] (OFBIZ-11306) POC for CSRF Token

2020-01-22 Thread James Yong (Jira)
[ https://issues.apache.org/jira/browse/OFBIZ-11306?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] James Yong updated OFBIZ-11306: --- Attachment: OFBIZ-11306.patch > POC for CSRF Token > -- > > Key:

[jira] [Updated] (OFBIZ-11306) POC for CSRF Token

2020-01-13 Thread Jacques Le Roux (Jira)
[ https://issues.apache.org/jira/browse/OFBIZ-11306?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Jacques Le Roux updated OFBIZ-11306: Description: CRSF tokens are generated using SecureRandom class. 1) In widget form where

[jira] [Updated] (OFBIZ-11306) POC for CSRF Token

2020-01-12 Thread James Yong (Jira)
[ https://issues.apache.org/jira/browse/OFBIZ-11306?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] James Yong updated OFBIZ-11306: --- Attachment: OFBIZ-11306.patch OFBIZ-11306_Plugins.patch > POC for CSRF Token >

[jira] [Updated] (OFBIZ-11306) POC for CSRF Token

2020-01-10 Thread James Yong (Jira)
[ https://issues.apache.org/jira/browse/OFBIZ-11306?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] James Yong updated OFBIZ-11306: --- Attachment: OFBIZ-11306.patch OFBIZ-11306_Plugins.patch > POC for CSRF Token >

[jira] [Updated] (OFBIZ-11306) POC for CSRF Token

2020-01-07 Thread James Yong (Jira)
[ https://issues.apache.org/jira/browse/OFBIZ-11306?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] James Yong updated OFBIZ-11306: --- Attachment: OFBIZ-11306.patch OFBIZ-11306_Plugins.patch > POC for CSRF Token >

[jira] [Updated] (OFBIZ-11306) POC for CSRF Token

2020-01-05 Thread James Yong (Jira)
[ https://issues.apache.org/jira/browse/OFBIZ-11306?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] James Yong updated OFBIZ-11306: --- Attachment: OFBIZ-11306.patch OFBIZ-11306_Plugins.patch > POC for CSRF Token >

[jira] [Updated] (OFBIZ-11306) POC for CSRF Token

2020-01-04 Thread James Yong (Jira)
[ https://issues.apache.org/jira/browse/OFBIZ-11306?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] James Yong updated OFBIZ-11306: --- Attachment: OFBIZ-11306_Plugins.patch > POC for CSRF Token > -- > >

[jira] [Updated] (OFBIZ-11306) POC for CSRF Token

2020-01-03 Thread James Yong (Jira)
[ https://issues.apache.org/jira/browse/OFBIZ-11306?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] James Yong updated OFBIZ-11306: --- Attachment: OFBIZ-11306.patch > POC for CSRF Token > -- > > Key:

[jira] [Updated] (OFBIZ-11306) POC for CSRF Token

2020-01-03 Thread James Yong (Jira)
[ https://issues.apache.org/jira/browse/OFBIZ-11306?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] James Yong updated OFBIZ-11306: --- Attachment: (was: OFBIZ-11306.patch) > POC for CSRF Token > -- > >

[jira] [Updated] (OFBIZ-11306) POC for CSRF Token

2020-01-03 Thread James Yong (Jira)
[ https://issues.apache.org/jira/browse/OFBIZ-11306?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] James Yong updated OFBIZ-11306: --- Attachment: OFBIZ-11306.patch > POC for CSRF Token > -- > > Key:

[jira] [Updated] (OFBIZ-11306) POC for CSRF Token

2020-01-03 Thread Jacques Le Roux (Jira)
[ https://issues.apache.org/jira/browse/OFBIZ-11306?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Jacques Le Roux updated OFBIZ-11306: Attachment: (was: OFBIZ-11306.patch) > POC for CSRF Token > -- > >

[jira] [Updated] (OFBIZ-11306) POC for CSRF Token

2020-01-03 Thread Jacques Le Roux (Jira)
[ https://issues.apache.org/jira/browse/OFBIZ-11306?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Jacques Le Roux updated OFBIZ-11306: Attachment: OFBIZ-11306.patch > POC for CSRF Token > -- > >

[jira] [Updated] (OFBIZ-11306) POC for CSRF Token

2019-12-31 Thread James Yong (Jira)
[ https://issues.apache.org/jira/browse/OFBIZ-11306?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] James Yong updated OFBIZ-11306: --- Attachment: OFBIZ-11306.patch > POC for CSRF Token > -- > > Key:

[jira] [Updated] (OFBIZ-11306) POC for CSRF Token

2019-12-29 Thread James Yong (Jira)
[ https://issues.apache.org/jira/browse/OFBIZ-11306?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] James Yong updated OFBIZ-11306: --- Attachment: OFBIZ-11306.patch > POC for CSRF Token > -- > > Key:

[jira] [Updated] (OFBIZ-11306) POC for CSRF Token

2019-12-27 Thread James Yong (Jira)
[ https://issues.apache.org/jira/browse/OFBIZ-11306?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] James Yong updated OFBIZ-11306: --- Attachment: OFBIZ-11306.patch > POC for CSRF Token > -- > > Key:

[jira] [Updated] (OFBIZ-11306) POC for CSRF Token

2019-12-26 Thread James Yong (Jira)
[ https://issues.apache.org/jira/browse/OFBIZ-11306?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] James Yong updated OFBIZ-11306: --- Attachment: OFBIZ-11306.patch > POC for CSRF Token > -- > > Key:

[jira] [Updated] (OFBIZ-11306) POC for CSRF Token

2019-12-21 Thread Jacques Le Roux (Jira)
[ https://issues.apache.org/jira/browse/OFBIZ-11306?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Jacques Le Roux updated OFBIZ-11306: Attachment: OFBIZ-11306.patch > POC for CSRF Token > -- > >

[jira] [Updated] (OFBIZ-11306) POC for CSRF Token

2019-12-18 Thread James Yong (Jira)
[ https://issues.apache.org/jira/browse/OFBIZ-11306?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] James Yong updated OFBIZ-11306: --- Attachment: OFBIZ-11306-v2.patch > POC for CSRF Token > -- > > Key:

[jira] [Updated] (OFBIZ-11306) POC for CSRF Token

2019-12-08 Thread Jacques Le Roux (Jira)
[ https://issues.apache.org/jira/browse/OFBIZ-11306?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Jacques Le Roux updated OFBIZ-11306: Attachment: (was: OFBIZ-11306.patch) > POC for CSRF Token > -- > >

[jira] [Updated] (OFBIZ-11306) POC for CSRF Token

2019-12-08 Thread Jacques Le Roux (Jira)
[ https://issues.apache.org/jira/browse/OFBIZ-11306?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Jacques Le Roux updated OFBIZ-11306: Attachment: OFBIZ-11306.patch > POC for CSRF Token > -- > >

[jira] [Updated] (OFBIZ-11306) POC for CSRF Token

2019-12-08 Thread Jacques Le Roux (Jira)
[ https://issues.apache.org/jira/browse/OFBIZ-11306?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Jacques Le Roux updated OFBIZ-11306: Attachment: OFBIZ-11306.patch > POC for CSRF Token > -- > >

[jira] [Updated] (OFBIZ-11306) POC for CSRF Token

2019-12-07 Thread James Yong (Jira)
[ https://issues.apache.org/jira/browse/OFBIZ-11306?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] James Yong updated OFBIZ-11306: --- Attachment: OFBIZ-11306.patch > POC for CSRF Token > -- > > Key: