CVE ID(s)
There's no CVE for this.
Report
I created a query to detect OGNL injections in Java code. The query raises a flag if user-provided OGNL expression is evaluated. OGNL library and Struts2 (OgnlUtil class) are supported.
The details are present in PR: github/codeql#3294
CVE ID(s)
There's no CVE for this.
Report
I created a query to detect OGNL injections in Java code. The query raises a flag if user-provided OGNL expression is evaluated. OGNL library and Struts2 (
OgnlUtilclass) are supported.The details are present in PR: github/codeql#3294