Issues
- 1
isValidInput failing for HTTPParameterValue {internalAction:getScreen}
#343 opened by GoogleCodeExporter - 0
StringUtilities.union() method is broken, weakens GenerateStrongPassword
#344 opened by GoogleCodeExporter - 0
Need to update Apache Commons BeanUtils
#340 opened by GoogleCodeExporter - 0
- 1
- 0
- 1
SecurityConfiguration for ESAPI.Encoder not found in ESAPI.properties. Using default: org.owasp.esapi.reference.DefaultEncoder
#339 opened by GoogleCodeExporter - 1
- 0
HttpParamtervalue for allowing Xml Data
#334 opened by GoogleCodeExporter - 0
HTTPParameterValue
#335 opened by GoogleCodeExporter - 0
- 3
Performance
#332 opened by GoogleCodeExporter - 0
-Log4JLogger.java doesn't output correct file & line number-Similar issue as reported in Issue 268
#333 opened by GoogleCodeExporter - 0
logger is gettin class cast exception
#329 opened by GoogleCodeExporter - 0
[deleted issue]
#330 opened by GoogleCodeExporter - 2
Regex in ESAPI.properties is not considering few of the french characters
#331 opened by GoogleCodeExporter - 1
Log4j configuration with no root level causes NPE in Log4jLogger.java
#327 opened by GoogleCodeExporter - 0
- 7
StringUtils.union broken which has minor impact on CSRF Protection and random file name generation
#323 opened by GoogleCodeExporter - 0
[deleted issue]
#324 opened by GoogleCodeExporter - 0
- 0
setHeader blocks legitimate headers due to header name size limit being too low
#326 opened by GoogleCodeExporter - 0
Construct "&" in Validator.URL is simple character class, not reference to ampersand
#322 opened by GoogleCodeExporter - 1
ClassCastException during web application redeploy due to the grift logging classes
#319 opened by GoogleCodeExporter - 0
- 1
Patch for /trunk/src/main/java/org/owasp/esapi/codecs/HTMLEntityCodec.java
#321 opened by GoogleCodeExporter - 5
RequestRateThrottleFilter may not work as expected with hits=1 or hits=2
#317 opened by GoogleCodeExporter - 1
PolicyFactory Sanitize method weird output
#318 opened by GoogleCodeExporter - 1
- 1
- 1
- 1
- 2
- 0
Deprecate current HttpUtilities.setRememberToken() and replace with one not requiring user password
#311 opened by GoogleCodeExporter - 0
- 5
ESAPI.properties file not being built / deployed as part of production downloads
#309 opened by GoogleCodeExporter - 1
Insecure default configuration for Executor.ApprovedExecutables in ESAPI.properties file
#307 opened by GoogleCodeExporter - 0
[deleted issue]
#308 opened by GoogleCodeExporter - 14
Crypto MAC by-pass makes default ESAPI symmetric encrytion using CBC mode vulnerable to padding oracle attacks
#306 opened by GoogleCodeExporter - 1
Make HTMLValidationRule to look for antisamy-esapi.xml in classpaths
#304 opened by GoogleCodeExporter - 1
- 0
AuthenticatedUser isCredentialsNonExpired() have todo comment, but default return false;
#302 opened by GoogleCodeExporter - 0
- 3
ClassCastException when using ESAPI logger
#299 opened by GoogleCodeExporter - 0
- 0
- 0
HTMLEntityCodec#decode incorrectly decodes upper-case accented letters as their lower-case counterparts
#296 opened by GoogleCodeExporter - 1
HTMLEntityCodec destroys 32-bit CJK (Chinese, Japanese and Korean) characters
#297 opened by GoogleCodeExporter - 0
encodeForCSS brakes color values
#298 opened by GoogleCodeExporter - 0