Skip to content
Snippets Groups Projects

Dependency updates to eliminate vulnerabilities discovered by dependency-check

Merged bhill6@wisc.edu requested to merge dependency_updates into main
1 file
+ 4
0
Compare changes
  • Side-by-side
  • Inline
@@ -96,6 +96,10 @@ public class DemonstrationOnlyPreAuthenticationConfiguration {
HttpServletRequest httpRequest = (HttpServletRequest) request;
String uri = httpRequest.getRequestURI();
String param = httpRequest.getParameter("_ignorepreauth");
// remove CRLF to avoid CWE-93
uri = (uri!=null) ? uri.replaceAll("([\\r\\n])", " ") : null;
param = (param!=null) ? param.replace("([\\r\\n])","") : null;
logger.debug("uri={}, param={}", uri, param);
if(null != param || IGNORED.contains(uri)) {
logger.info("skipping PreAuthenticationSimulationServletFilter, either due to '_ignorepreauth' or visiting ignore uri");
Loading