struts-dev mailing list archives

Site index · List index
Message view « Date » · « Thread »
Top « Date » · « Thread »
From Lukasz Lenart <>
Subject Ultimate way to solve problems with Ognl
Date Sat, 03 May 2014 15:55:38 GMT

I'm working on solution to close the security gap in how we use Ognl
inside Struts. The changes are here [1] and based on idea to exclude
certain classes from evaluation, eg. Object, Runtime.

What do you think about that? And what other class should I exclude?
I'm planning to have it configurable but the default provided by
framework must be strong.


+ 48 606 323 122

To unsubscribe, e-mail:
For additional commands, e-mail:

View raw message