Link Details

Link 95526 thumbnail
User 233197 avatar

By Miche
via searchsoftwarequality.techtarget.com
Published: Jul 17 2008 / 10:56

Ounce Labs recently discovered two vulnerabilities that can affect Java Web applications that use the Spring Framework. The company is working with SpringSource to ensure developers know how to protect against these security issues.
  • 6
  • 1
  • 1054
  • 385

Comments

Add your comment
User 281687 avatar

paul_houle replied ago:

0 votes Vote down Vote up Reply

Points out an important issue with frameworks in general, despite an annoying interstitial ad. (At least this one doesn't crash Firefox)

User 306406 avatar

MichaelMinella replied ago:

0 votes Vote down Vote up Reply

The issue is not with the Spring Framework. It is with Spring MVC. Being unclear about things like this can have serious impacts on the acceptance of open source in an enterprise.

User 167926 avatar

cwilkes replied ago:

0 votes Vote down Vote up Reply

At first I thought this was a joke as I got a 500 error when loading up this dzone page :)
javax.el.PropertyNotFoundException: List.getIndex '1' is an invalid index for list of length '1'
....
at com.dzone.utils.filters.WhosOnlineFilter.doFilter(WhosOnlineFilter.java:136)

User 279827 avatar

DarrenDarren replied ago:

0 votes Vote down Vote up Reply

Even 2+ years ago, I remember seeing warnings in the Spring MVC documentation to always use "setAllowedFields" to prevent malicious values inserted into your form-backing objects. It's good to raise awareness among Spring MVC developers, but this is hardly a discovery.

Add your comment


Html tags not supported. Reply is editable for 5 minutes. Use [code lang="java|ruby|sql|css|xml"][/code] to post code snippets.

Voters For This Link (6)



Voters Against This Link (1)