diff --git a/pig-common/pig-common-bom/pom.xml b/pig-common/pig-common-bom/pom.xml index 860378629..029822e12 100644 --- a/pig-common/pig-common-bom/pom.xml +++ b/pig-common/pig-common-bom/pom.xml @@ -22,7 +22,7 @@ 17 17 1.2.83_noneautotype - 3.1.0 + 3.0.3 2.3.0 2.2.20 3.5.5 diff --git a/pig-common/pig-common-xss/src/main/java/com/pig4cloud/pig/common/xss/utils/XssUtil.java b/pig-common/pig-common-xss/src/main/java/com/pig4cloud/pig/common/xss/utils/XssUtil.java index 34f1a231d..ec8174c7c 100644 --- a/pig-common/pig-common-xss/src/main/java/com/pig4cloud/pig/common/xss/utils/XssUtil.java +++ b/pig-common/pig-common-xss/src/main/java/com/pig4cloud/pig/common/xss/utils/XssUtil.java @@ -102,7 +102,7 @@ public HtmlSafeList() { } @Override - protected boolean isSafeAttribute(String tagName, Element el, Attribute attr) { + public boolean isSafeAttribute(String tagName, Element el, Attribute attr) { // 不允许 javascript 开头的 src 和 href if ("src".equalsIgnoreCase(attr.getKey()) || "href".equalsIgnoreCase(attr.getKey())) { String value = attr.getValue();