-
Type:
Bug
-
Resolution: Fixed
-
Priority:
Medium
-
Affects Version/s: 2.10.0, 3.0.0, 3.7.0
-
Component/s: None
It is possible to fake log entries in FishEye/Crucible logs, by sending specially crafted http requests containing a newline character.
For example going to the url /changelog/asd%0AFake%20log%20entry will cause the following to be logged:
2015-03-24 09:59:09,564 INFO [qtp1610928748-315 ] fisheye ServletUtils-send404 - 404: No such repository: asd
Fake log entry referer=null