[OpenNMS/opennms] ce007f: NMS-20245: Fix SQL injection in Asset Management J...
Chandra Gorantla via opennms-cvs <[email protected]>
| Newsgroups | gmane.network.opennms.cvs |
|---|---|
| Message-ID | <OpenNMS/opennms/push/refs/heads/cg/jira/NMS-20245/[email protected]> |
Branch: refs/heads/cg/jira/NMS-20245
Home: https://github.com/OpenNMS/opennms
Commit: ce007f01a7fa963a4d6e2545332d34e2bc582d1f
https://github.com/OpenNMS/opennms/commit/ce007f01a7fa963a4d6e2545332d34e2bc582d1f
Author: Chandra Gorantla <[email protected]>
Date: 2026-08-20 (Thu, 20 Aug 2026)
Changed paths:
M opennms-base-assembly/src/main/filtered/etc/report-templates/AssetManagementMaintExpired.jrxml
M opennms-base-assembly/src/main/filtered/etc/report-templates/AssetManagementMaintStrategy.jrxml
Log Message:
-----------
NMS-20245: Fix SQL injection in Asset Management JasperReports
Bind the user-prompted DATE_FORMAT/threshold params ($P{}) instead of literal
$P!{} substitution in AssetManagementMaintExpired and AssetManagementMaintStrategy.
To unsubscribe from these emails, change your notification settings at https://github.com/OpenNMS/opennms/settings/notifications
_______________________________________________
Please read the OpenNMS Mailing List FAQ:
http://www.opennms.org/wiki/index.php?page=MailingListFaq
opennms-cvs mailing list
To *unsubscribe* or change your subscription options, see the bottom of this page:
https://lists.sourceforge.net/lists/listinfo/opennms-cvs