Skip to content
Snippets Groups Projects

Dependency updates to eliminate vulnerabilities discovered by dependency-check

Merged bhill6@wisc.edu requested to merge dependency_updates into main
@@ -98,9 +98,9 @@ public class DemonstrationOnlyPreAuthenticationConfiguration {
String param = httpRequest.getParameter("_ignorepreauth");
// remove CRLF to avoid CWE-93
uri = (uri!=null) ? uri.replaceAll("([\\r\\n])", " ") : null;
param = (param!=null) ? param.replace("([\\r\\n])","") : null;
logger.debug("uri={}, param={}", uri, param);
String cleanUri = (uri!=null) ? uri.replaceAll("([\\r\\n])", " ") : null;
String cleanParam = (param!=null) ? param.replace("([\\r\\n])","") : null;
logger.debug("uri={}, param={}", cleanUri, cleanParam);
if(null != param || IGNORED.contains(uri)) {
logger.info("skipping PreAuthenticationSimulationServletFilter, either due to '_ignorepreauth' or visiting ignore uri");
filterChain.doFilter(request, response);
Loading