Issues
- ESAPI configuration files not included in dist.ESAPILEG-340Max Gelman
- User session just jumped from unknown to 0:0:0:0:0:0:0:1ESAPILEG-339
- EncryptedPropertiesUtils Switch for Adding ValuesESAPILEG-338
- HTTPParameterValueESAPILEG-337
- HttpParamtervalue for allowing Xml DataESAPILEG-336
- -Log4JLogger.java doesn't output correct file & line number-Similar issue as reported in Issue 268ESAPILEG-335
- PerformanceESAPILEG-334KevinW
- Regex in ESAPI.properties is not considering few of the french charactersESAPILEG-333
- logger is gettin class cast exceptionESAPILEG-332
- Content Security Policy - Java Servlet FilterESAPILEG-331
- Log4j configuration with no root level causes NPE in Log4jLogger.javaESAPILEG-330
- setHeader blocks legitimate headers due to header name size limit being too lowESAPILEG-329KevinW
- AbstractAccessReferenceMap.addDirectReference not invariantESAPILEG-328
- StringUtils.union broken which has minor impact on CSRF Protection and random file name generationESAPILEG-327
- Construct "&" in Validator.URL is simple character class, not reference to ampersandESAPILEG-326
- Patch for /trunk/src/main/java/org/owasp/esapi/codecs/HTMLEntityCodec.javaESAPILEG-325
- ClassCastException on SecurityWrapperResponseESAPILEG-324
- ClassCastException during web application redeploy due to the grift logging classesESAPILEG-323
- PolicyFactory Sanitize method weird outputESAPILEG-322Resolved issue: ESAPILEG-322
- RequestRateThrottleFilter may not work as expected with hits=1 or hits=2ESAPILEG-321
- Unsynchronized get method, synchronized set methodESAPILEG-320
- Incorrect lazy initialization of static field instanceESAPILEG-319
- Resource leak: FileInputStream is not closed on method exitESAPILEG-318
- Incorrect Equality test on floating point valuesESAPILEG-317
- Resource leak: This FileReader is not closed on method exitESAPILEG-316
- Deprecate current HttpUtilities.setRememberToken() and replace with one not requiring user passwordESAPILEG-315
- ValidatorTest.testIsValidDate fails if default locale is not USESAPILEG-314
- ESAPI.properties file not being built / deployed as part of production downloadsESAPILEG-313
- Insecure default configuration for Executor.ApprovedExecutables in ESAPI.properties fileESAPILEG-312
- Crypto MAC by-pass makes default ESAPI symmetric encrytion using CBC mode vulnerable to padding oracle attacksESAPILEG-311
- Double checked locking on Log4JLogFactory.getInstance()ESAPILEG-310Resolved issue: ESAPILEG-310
- Make HTMLValidationRule to look for antisamy-esapi.xml in classpathsESAPILEG-309
- Eliminate eclipse code warnings to improve qualityESAPILEG-308
- AuthenticatedUser isCredentialsNonExpired() have todo comment, but default return false;ESAPILEG-307
- Issue with decodeFromURL method in the DefaultEncoderESAPILEG-306
- Canonicaling "&ESAPILEG-37;Device&ESAPILEG-37; changes the meaning of the input stringESAPILEG-305
- ClassCastException when using ESAPI loggerESAPILEG-304
- encodeForCSS brakes color valuesESAPILEG-303
- HTMLEntityCodec destroys 32-bit CJK (Chinese, Japanese and Korean) charactersESAPILEG-302
- HTMLEntityCodec#decode incorrectly decodes upper-case accented letters as their lower-case counterpartsESAPILEG-301
- encodeForHTMLAttribute escapes the forward slashESAPILEG-300
- non-BMP characters incorrectly encodedESAPILEG-299
- isValidDate fails with patterns ending with "yyyy"ESAPILEG-298
- Java 7 J2EE StandardSessionFacade is not comparableESAPILEG-297
- ClassNotFoundException: org.owasp.esapi.reference.accesscontrol.DefaultAccessController AccessController classESAPILEG-296
- CSS and images not working with ESAPIWebApplicationFirewallFilterESAPILEG-295
- ESAPI validator isValidRedirectLocation does not workESAPILEG-294
- Config ErrorESAPILEG-293
- Canoniclizing out of EncodeforLdap or EncodeForDN if contains specific characters like "(, ) #" etc. messes up the input.ESAPILEG-292
- jsessionid validator regex in esapi.properties not applicable to ids generated by tomcatESAPILEG-291
50 of 338