[
https://issues.apache.org/jira/browse/CODEC-346?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
]
Gary D. Gregory resolved CODEC-346.
-----------------------------------
Resolution: Information Provided
I am resolving this as expected behavior, see CODEC-280 and CODEC-289. Version
1.15 restored lenient decoding by default and introduced an explicit strict
policy.
Applications requiring canonical values should explicitly select strict
decoding. Changing the default would introduce another compatibility break.
> Base64 decoder accepts non-canonical input rejected in versions 1.13 and 1.14
> -----------------------------------------------------------------------------
>
> Key: CODEC-346
> URL: https://issues.apache.org/jira/browse/CODEC-346
> Project: Commons Codec
> Issue Type: Bug
> Affects Versions: 1.15, 1.16, 1.16.1, 1.22.1
> Reporter: Xiaoyan Zang
> Priority: Major
>
> While testing client code that uses different versions of Commons Codec, I
> noticed a change in Base64 decoding behavior related to CODEC-134.
> For example, the input {{"ZE=="}} is rejected when the client uses versions
> 1.13 and 1.14, with an {{{}IllegalArgumentException{}}}. However, starting
> with version 1.15, the same client code accepts the input and successfully
> decodes it.
> Based on my testing, this appears to reproduce the vulnerable behavior
> originally discussed in CODEC-134 when using the default decoding behavior.
> Is this change expected in 1.15 and later?
--
This message was sent by Atlassian Jira
(v8.20.10#820010)