[ 
https://issues.apache.org/jira/browse/CODEC-346?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
 ]

Gary D. Gregory resolved CODEC-346.
-----------------------------------
    Resolution: Information Provided

I am resolving this as expected behavior, see CODEC-280 and CODEC-289. Version 
1.15 restored lenient decoding by default and introduced an explicit strict 
policy.

Applications requiring canonical values should explicitly select strict 
decoding. Changing the default would introduce another compatibility break.

> Base64 decoder accepts non-canonical input rejected in versions 1.13 and 1.14
> -----------------------------------------------------------------------------
>
>                 Key: CODEC-346
>                 URL: https://issues.apache.org/jira/browse/CODEC-346
>             Project: Commons Codec
>          Issue Type: Bug
>    Affects Versions: 1.15, 1.16, 1.16.1, 1.22.1
>            Reporter: Xiaoyan Zang
>            Priority: Major
>
> While testing client code that uses different versions of Commons Codec, I 
> noticed a change in Base64 decoding behavior related to CODEC-134.
> For example, the input {{"ZE=="}} is rejected when the client uses versions 
> 1.13 and 1.14, with an {{{}IllegalArgumentException{}}}. However, starting 
> with version 1.15, the same client code accepts the input and successfully 
> decodes it.
> Based on my testing, this appears to reproduce the vulnerable behavior 
> originally discussed in CODEC-134 when using the default decoding behavior.
> Is this change expected in 1.15 and later?



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to