Skip to content

New Rule : Seam Logger usage could lead to remote code execution #56

@ThrawnCA

Description

@ThrawnCA

The Seam framework accepts expression language in its log statements, so concatenating strings to pass to the logger is a very bad idea.

https://issues.jboss.org/browse/JBSEAM-5130

Is it easy enough to add a detector for this?

Metadata

Metadata

Assignees

Labels

enhancementNew feature or improvement to existing detector.

Type

No type

Projects

No projects

Milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions