You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
We found incorrect behaviour in Language System. If an user has some incorrect data in cookies, dotcms writes to logs the NumberFormat exception like this:
ERROR com.dotmarketing.portlets.languagesmanager.business.LanguageFactoryImpl - getLanguage failed passed id is not numeric.
java.lang.NumberFormatException:
For input string: "if(now()=sysdate(),sleep(26),0)/*'XOR(if(now()=sysdate(),sleep(26),0))OR'"XOR(if(now()=sysdate(),sleep(26),0))OR"*/"
03:26:43,237 INFO [stdout] (Log4J Active Asynchronous Appender) at java.lang.NumberFormatException.forInputString(NumberFormatException.java:65)
03:26:43,237 INFO [stdout] (Log4J Active Asynchronous Appender) at java.lang.Long.parseLong(Long.java:441)
03:26:43,238 INFO [stdout] (Log4J Active Asynchronous Appender) at java.lang.Long.parseLong(Long.java:483)
Our case:
Someone tried to break our site through a large number of incorrect requests with invalid language id.
And as a result our log began to weigh 21 gigabytes and disk space is over.
Maybe the best solution is not to write this information to logs?
The text was updated successfully, but these errors were encountered:
This issue has been automatically marked as stale because it has not had activity within the past 90 days. It will be closed in 30 days no further activity occurs. Thank you.
We found incorrect behaviour in Language System. If an user has some incorrect data in cookies, dotcms writes to logs the NumberFormat exception like this:
Our case:
Someone tried to break our site through a large number of incorrect requests with invalid language id.
And as a result our log began to weigh 21 gigabytes and disk space is over.
Maybe the best solution is not to write this information to logs?
The text was updated successfully, but these errors were encountered: