Suvarna Garge (Editor)

OGNL

Updated on
Edit
Like
Comment
Share on FacebookTweet on TwitterShare on LinkedInShare on Reddit
Developer(s)
  
OGNL Technology

Operating system
  
Cross-platform

Written in
  
Java

Platform
  
Java Virtual Machine

Stable release
  
3.0.8 / September 24, 2013 (2013-09-24)

Type
  
Expression Language (EL)

Object-Graph Navigation Language (OGNL) is an open-source Expression Language (EL) for Java, which, while using simpler expressions than the full range of those supported by the Java language, allows getting and setting properties (through defined setProperty and getProperty methods, found in JavaBeans), and execution of methods of Java classes. It also allows for simpler array manipulation.

Contents

It is aimed to be used in Java EE applications with taglibs as expression language.

OGNL was created by Luke Blanshard and Drew Davidson of OGNL Technology. OGNL development was continued by OpenSymphony, which closed in 2011. OGNL is developed now as a part of the Apache Commons.

OGNL Technology

OGNL began as a way to map associations between front-end components and back-end objects using property names. As these associations gathered more features, Drew Davidson created Key-Value Coding language (KVCL). Luke Blanshard then reimplemented KVCL using ANTLR and started using the name OGNL. The technology was again reimplemented using the Java Compiler Compiler (JavaCC).

OGNL uses Java reflection and introspection to address the Object Graph of the runtime application. This allows the program to change behavior based on the state of the object graph instead of relying on compile time settings. It also allows changes to the object graph.

Projects using OGNL

  • WebWork and its successor Struts2
  • Tapestry (4 and earlier)
  • Spring Web Flow
  • Apache Click
  • MyBatis - SQL mapper framework
  • The Thymeleaf - A Java XML/XHTML/HTML5 template engine
  • FreeMarker - A Java template engine
  • OGNL Security Issues

    Due to its ability to create or change executable code, OGNL is capable of introducing critical security flaws to any framework that uses it. Multiple Apache Struts2 versions have been vulnerable OGNL security flaws. As of October 2013, the recommended secure version of Struts2 is 2.3.15.2, released on September 20, 2013. Users are urged to upgrade to the latest version.

    For example, Apache Struts versions 2.0.0 through 2.3.15 allow remote attackers to execute arbitrary OGNL expressions via a parameter prefixed with action:, redirect:, or redirectAction:. Exploit code for this vulnerability was released for the Metasploit framework on July 7, 2013.

    References

    OGNL Wikipedia