Link: Spring-MVC Cross-Site Scripting Vulnerabilities
Sverre Huseby examines some security issues with Spring-MVC. As it turns out, the Spring JSP form-taglib provide no HTML-escaping by default, making it very easy to get Cross-Site Scripting vulnerabilities included in the code. The article comes complete with a standalone application that illustrates the problem.
This work is licensed under a
Creative Commons Attribution 3.0 License.
Print This Post
Add New Comment
Viewing 6 Comments
Thanks. Your comment is awaiting approval by a moderator.
Do you already have an account? Log in and claim this comment.
Do you already have an account? Log in and claim this comment.
Do you already have an account? Log in and claim this comment.
But the issue should be reported to the Spring team *as well*. And I trust Sverre is one step ahead of us on this.
Do you already have an account? Log in and claim this comment.
Do you already have an account? Log in and claim this comment.
Do you already have an account? Log in and claim this comment.
And I've been informed that the only _bug_ I point at is being fixed in the next 2.0.x release. Not because of me, but because someone reported it the day after I started mailing my thoughts to some friends.
The design flaw may be (maybe) addressed in the next 2.x.y release.
Do you already have an account? Log in and claim this comment.
default" to its list of fundamental design principles."
Well if that happened, then Sverre could well be out of a lot of consulting revenue!
Add New Comment