[jira] [Updated] (OFBIZ-6522) Potential IndexOutOfBoundsException in CategoryServices.getProductCategoryAndLimitedMembers

Previous Topic Next Topic
 
classic Classic list List threaded Threaded
1 message Options
Reply | Threaded
Open this post in threaded view
|

[jira] [Updated] (OFBIZ-6522) Potential IndexOutOfBoundsException in CategoryServices.getProductCategoryAndLimitedMembers

Nicolas Malin (Jira)

     [ https://issues.apache.org/jira/browse/OFBIZ-6522?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ]

Michael Brohl updated OFBIZ-6522:
---------------------------------
    Fix Version/s:     (was: Upcoming Branch)
                   15.12.01

> Potential IndexOutOfBoundsException in CategoryServices.getProductCategoryAndLimitedMembers
> -------------------------------------------------------------------------------------------
>
>                 Key: OFBIZ-6522
>                 URL: https://issues.apache.org/jira/browse/OFBIZ-6522
>             Project: OFBiz
>          Issue Type: Bug
>          Components: product
>    Affects Versions: Upcoming Branch
>            Reporter: Martin Becker
>            Assignee: Michael Brohl
>            Priority: Minor
>             Fix For: 15.12.01
>
>         Attachments: OFBIZ-6522.patch
>
>
> If view indexes as input parameters of service getProductCategoryAndLimitedMembers get manipulated (e.g. by manipulating URL params or bookmarking an URL with those params an come back later), it can lead to an IndexOutOfBoundsException because of a lowIndex greater list size. The highIndex is checked for that, the lowIndex is not.



--
This message was sent by Atlassian JIRA
(v6.3.4#6332)