File tomcat-8.0.53-CVE-2019-0221.patch of Package tomcat.15152
From 44ec74c44dcd05cd7e90967c04d40b51440ecd7e Mon Sep 17 00:00:00 2001
From: Mark Thomas <markt@apache.org>
Date: Mon, 11 Mar 2019 11:33:03 +0000
Subject: [PATCH] Escape debug output to aid readability
# Conflicts:
# java/org/apache/catalina/ssi/SSIPrintenv.java
---
java/org/apache/catalina/ssi/SSIPrintenv.java | 5 ++---
webapps/docs/changelog.xml | 3 +++
2 files changed, 5 insertions(+), 3 deletions(-)
Index: java/org/apache/catalina/ssi/SSIPrintenv.java
===================================================================
--- java/org/apache/catalina/ssi/SSIPrintenv.java.orig
+++ java/org/apache/catalina/ssi/SSIPrintenv.java
@@ -43,8 +43,7 @@ public class SSIPrintenv implements SSIC
Iterator<String> iter = variableNames.iterator();
while (iter.hasNext()) {
String variableName = iter.next();
- String variableValue = ssiMediator
- .getVariableValue(variableName);
+ String variableValue = ssiMediator.getVariableValue(variableName, "entity");
//This shouldn't happen, since all the variable names must
// have values
if (variableValue == null) {