Browse Source

SEC-967: TextUtils.java does not escape ampersand character

http://jira.springframework.org/browse/SEC-967. Added escaping of '&' character
2.0.x
Luke Taylor 18 years ago
parent
commit
4e2d6f8b2e
  1. 2
      core/src/main/java/org/springframework/security/util/TextUtils.java

2
core/src/main/java/org/springframework/security/util/TextUtils.java

@ -26,6 +26,8 @@ public abstract class TextUtils { @@ -26,6 +26,8 @@ public abstract class TextUtils {
sb.append(""");
} else if (c == '\'') {
sb.append("'");
} else if (c == '&') {
sb.append("&");
} else {
sb.append(c);
}

Loading…
Cancel
Save