Details
-
Bug
-
Status: Closed
-
Major
-
Resolution: Fixed
-
1.0-beta2
-
None
Description
The ParametersInterceptor evaluates all parameter names using OGNL. This allows an attacker to execute code such as
@System@exit(1).dummy