jmestwa-coder opened a new pull request, #4316: URL: https://github.com/apache/logging-log4j2/pull/4316
`DumpTag` (`log:dump`) writes the names and values of every attribute in the selected scope straight into the page: - request- and session-scope attributes are routinely attacker-influenced (a request parameter copied into a request attribute, a form bean, etc.), so any page using `log:dump` with those scopes emits reflected/stored XSS - `doEndTag` concatenated the attribute `name` and `value` into the HTML output with no escaping - both are now escaped with `StringBuilders.escapeXml` before writing, the same escaping `HtmlLayout` and `Log4j1XmlLayout` already apply to event data ## Checklist - [x] Base your changes on the `2.x` branch - [x] `./mvnw verify` succeeds for the affected module - [x] Changelog entry added under `src/changelog/.2.x.x` - [x] Tests are provided -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
