summaryrefslogtreecommitdiffstats
path: root/ecomp-sdk/epsdk-app-common/src/main/java/org/onap/portalapp/util/SecurityXssValidator.java
diff options
context:
space:
mode:
authorManoop Talasila <talasila@research.att.com>2019-10-29 14:29:29 +0000
committerGerrit Code Review <gerrit@onap.org>2019-10-29 14:29:29 +0000
commitbeabe647ed84f9a5fea3e9633267e713e19f3750 (patch)
treeb24086168eb30b8beed86a6a5096a7ea996d3698 /ecomp-sdk/epsdk-app-common/src/main/java/org/onap/portalapp/util/SecurityXssValidator.java
parent7589db2190a9b63d6cd3632e0f9694df88700f10 (diff)
parenteae3e8b357d96bff29ce0b3086aed388754feaf2 (diff)
Merge "Security Vulnerability in pom.xml fix"
Diffstat (limited to 'ecomp-sdk/epsdk-app-common/src/main/java/org/onap/portalapp/util/SecurityXssValidator.java')
-rw-r--r--ecomp-sdk/epsdk-app-common/src/main/java/org/onap/portalapp/util/SecurityXssValidator.java4
1 files changed, 2 insertions, 2 deletions
diff --git a/ecomp-sdk/epsdk-app-common/src/main/java/org/onap/portalapp/util/SecurityXssValidator.java b/ecomp-sdk/epsdk-app-common/src/main/java/org/onap/portalapp/util/SecurityXssValidator.java
index 69807a1c..c964712d 100644
--- a/ecomp-sdk/epsdk-app-common/src/main/java/org/onap/portalapp/util/SecurityXssValidator.java
+++ b/ecomp-sdk/epsdk-app-common/src/main/java/org/onap/portalapp/util/SecurityXssValidator.java
@@ -43,8 +43,8 @@ import java.util.concurrent.locks.Lock;
import java.util.concurrent.locks.ReentrantLock;
import java.util.regex.Pattern;
import org.apache.commons.lang.NotImplementedException;
+import org.apache.commons.lang.StringEscapeUtils;
import org.apache.commons.lang.StringUtils;
-import org.apache.commons.lang3.StringEscapeUtils;
import org.onap.portalsdk.core.logging.logic.EELFLoggerDelegate;
import org.onap.portalsdk.core.util.SystemProperties;
import org.owasp.esapi.ESAPI;
@@ -132,7 +132,7 @@ public class SecurityXssValidator {
if (StringUtils.isNotBlank(value)) {
- value = StringEscapeUtils.escapeHtml4(value);
+ value = StringEscapeUtils.escapeHtml(value);
value = ESAPI.encoder().canonicalize(value);