-
Type:
Bug
-
Status: Closed
-
Priority:
Minor
-
Resolution: Fixed
-
Affects Version/s: 5.2 EE SP5 (5.2.9) , 6.0 EE (6.0.10), 6.0 EE SP1 (6.0.11), 6.0 EE SP2 (6.0.12), 6.1 EE GA1 (6.1.10), 6.1 EE GA2 (6.1.20), 6.1 EE GA3 (6.1.30), 6.1.X EE, 6.2 EE GA1 (6.2.10), 6.2.X EE
-
Component/s: Application Security
-
Fix Pack Version/s:
The fix adds a new property to the portal configuration:
struts.portlet.ignored.parameters.regexp=(.\\.|^|.|\\[('|"))(c|C)lass(
.|('|")]|[).*
If necessary, this default value can be overridden in the portal-ext.properties file.