This is an automated email from the ASF dual-hosted git repository.

remm pushed a commit to branch 9.0.x
in repository https://gitbox.apache.org/repos/asf/tomcat.git


The following commit(s) were added to refs/heads/9.0.x by this push:
     new 3fc8342b Improve escaping for code in call method
3fc8342b is described below

commit 3fc8342b510f90a9ec0a51b34b40046a297899d6
Author: remm <r...@apache.org>
AuthorDate: Sat Jan 1 20:56:08 2022 +0100

    Improve escaping for code in call method
---
 java/org/apache/tomcat/util/digester/CallMethodRule.java | 4 ++--
 1 file changed, 2 insertions(+), 2 deletions(-)

diff --git a/java/org/apache/tomcat/util/digester/CallMethodRule.java 
b/java/org/apache/tomcat/util/digester/CallMethodRule.java
index 43ae843..bd65535 100644
--- a/java/org/apache/tomcat/util/digester/CallMethodRule.java
+++ b/java/org/apache/tomcat/util/digester/CallMethodRule.java
@@ -393,9 +393,9 @@ public class CallMethodRule extends Rule {
                     code.append(", ");
                 }
                 if (bodyText != null) {
-                    code.append("\"").append(bodyText).append("\"");
+                    
code.append("\"").append(IntrospectionUtils.escape(bodyText)).append("\"");
                 } else if (paramValues[i] instanceof String) {
-                    
code.append("\"").append(paramValues[i].toString()).append("\"");
+                    
code.append("\"").append(IntrospectionUtils.escape(paramValues[i].toString())).append("\"");
                 } else {
                     code.append(digester.toVariableName(paramValues[i]));
                 }

---------------------------------------------------------------------
To unsubscribe, e-mail: dev-unsubscr...@tomcat.apache.org
For additional commands, e-mail: dev-h...@tomcat.apache.org

Reply via email to