| Age | Commit message (Collapse) | Author | Files | Lines | 
|---|
|  | factory | 
|  |  | 
|  |  | 
|  |  | 
|  |  | 
|  | cve-2022-22965 | 
|  | setDisallowedFields | 
|  |  | 
|  |  | 
|  | disallowed files for DataBinder
  This code protects Spring Core from a "Remote Code Execution" attack (dubbed "Spring4Shell").This is a midigation for
  For more details, see this post: https://www.lunasec.io/docs/blog/spring-rce-vulnerabilities/ | 
|  |  | 
|  |  | 
|  |  | 
|  | Spring locale-resolver | 
|  | Spring now | 
|  |  | 
|  | 'AuthenticatedEncryptionPendingRequestIdGenerationStrategy' that allows generation of already expired tokens | 
|  |  | 
|  |  | 
|  |  | 
|  | openSAML4.x API | 
|  |  | 
|  | circular-dependencies loading | 
|  | Spring MVC architecture | 
|  |  | 
|  | # Conflicts:
#	eaaf_modules/eaaf_module_pvp2_core/src/main/java/at/gv/egiz/eaaf/modules/pvp2/impl/metadata/PvpMetadataResolverAdapter.java
#	eaaf_modules/eaaf_module_pvp2_core/src/main/java/at/gv/egiz/eaaf/modules/pvp2/impl/verification/SamlVerificationEngine.java
#	eaaf_modules/eaaf_module_pvp2_core/src/test/java/at/gv/egiz/eaaf/modules/pvp2/test/binding/SoapBindingTest.java
#	eaaf_modules/eaaf_module_pvp2_core/src/test/java/at/gv/egiz/eaaf/modules/pvp2/test/dummy/DummyMetadataProvider.java
#	eaaf_modules/eaaf_module_pvp2_idp/src/main/java/at/gv/egiz/eaaf/modules/pvp2/idp/impl/AbstractPvp2XProtocol.java
#	eaaf_modules/eaaf_module_pvp2_sp/src/main/java/at/gv/egiz/eaaf/modules/pvp2/sp/impl/PvpAuthnRequestBuilder.java
#	pom.xml | 
|  |  | 
|  |  | 
|  |  | 
|  | 'ModuleRegistration', and 'AuthModule' implementations | 
|  |  | 
|  |  | 
|  |  | 
|  |  | 
|  |  | 
|  |  | 
|  | contentType without rendering | 
|  |  | 
|  |  | 
|  |  | 
|  |  | 
|  |  | 
|  |  | 
|  |  | 
|  |  | 
|  |  | 
|  |  | 
|  |  | 
|  |  | 
|  | does not responde |