Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Investigate solutions fir Access Control Bypass issues with jsp tags #81

Open
meg23 opened this issue Nov 13, 2014 · 4 comments
Open

Investigate solutions fir Access Control Bypass issues with jsp tags #81

meg23 opened this issue Nov 13, 2014 · 4 comments

Comments

@meg23
Copy link

meg23 commented Nov 13, 2014

From chrisisbeef on December 04, 2009 20:56:45

It is possible to access restricted resources and bypass access control on
those resources on pages that use the jsp forward and include tags.

Ref: https://lists.owasp.org/pipermail/owasp-esapi/2009-December/001672.html

Original issue: http://code.google.com/p/owasp-esapi-java/issues/detail?id=71

@meg23
Copy link
Author

meg23 commented Nov 13, 2014

From chrisisbeef on November 06, 2010 01:20:56

Is there momentum to get this into 2.0? This seems like a low traffic bug and something that would be nice to have, but I don't think this is a requirement for 2.0

@meg23
Copy link
Author

meg23 commented Nov 13, 2014

From manico.james@gmail.com on November 18, 2010 18:34:58

Labels: AccessControl

@meg23
Copy link
Author

meg23 commented Nov 13, 2014

From chrisisbeef on November 20, 2010 13:53:46

Labels: -AccessControl Component-AccessControl

@meg23
Copy link
Author

meg23 commented Nov 13, 2014

From chris.sc...@owasp.org on March 23, 2011 09:33:44

Moved out of 2.0 release

Labels: -Priority-High -Milestone-Release2.0 Priority-Medium Milestone-Release2.1

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

1 participant