Skip to content
Snippets Groups Projects

Dependency updates to eliminate vulnerabilities discovered by dependency-check

Merged bhill6@wisc.edu requested to merge dependency_updates into main
Files
4
@@ -96,7 +96,11 @@ public class DemonstrationOnlyPreAuthenticationConfiguration {
HttpServletRequest httpRequest = (HttpServletRequest) request;
String uri = httpRequest.getRequestURI();
String param = httpRequest.getParameter("_ignorepreauth");
logger.debug("uri={}, param={}", uri, param);
// remove CRLF to avoid CWE-93
String cleanUri = (uri!=null) ? uri.replaceAll("([\\r\\n])", " ") : null;
String cleanParam = (param!=null) ? param.replace("([\\r\\n])","") : null;
logger.debug("uri={}, param={}", cleanUri, cleanParam);
if(null != param || IGNORED.contains(uri)) {
logger.info("skipping PreAuthenticationSimulationServletFilter, either due to '_ignorepreauth' or visiting ignore uri");
filterChain.doFilter(request, response);
Loading