Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion android/guava/src/com/google/common/net/MediaType.java
Original file line number Diff line number Diff line change
Expand Up @@ -1255,7 +1255,7 @@ private static String escapeAndQuote(String value) {
StringBuilder escaped = new StringBuilder(value.length() + 16).append('"');
for (int i = 0; i < value.length(); i++) {
char ch = value.charAt(i);
if (ch == '\r' || ch == '\\' || ch == '"') {
if (ch == '\r' || ch == '\n' || ch == '\\' || ch == '"') {
escaped.append('\\');
}
escaped.append(ch);
Expand Down
19 changes: 19 additions & 0 deletions guava-tests/test/com/google/common/net/MediaTypeTest.java
Original file line number Diff line number Diff line change
Expand Up @@ -494,4 +494,23 @@ public void testToString() {
"text/plain; something=\"cr@zy\"; something-else=\"crazy with spaces\";"
+ " and-another-thing=\"\"; normal-thing=foo");
}

public void testEscapeAndQuote_newlineEscaped() {
// Newline characters must be escaped in quoted parameter values to prevent
// HTTP header injection when MediaType.toString() is used in HTTP headers.
MediaType mediaType =
MediaType.create("text", "plain").withParameter("param", "value\ninjected");
String result = mediaType.toString();
// The \n must be backslash-escaped, not present as a raw 0x0A byte
assertThat(result).doesNotContain("\n");
assertThat(result).isEqualTo("text/plain; param=\"value\\\ninjected\"");
}

public void testEscapeAndQuote_crEscaped() {
// Carriage return was already escaped (pre-existing behavior)
MediaType mediaType =
MediaType.create("text", "plain").withParameter("param", "value\rinjected");
String result = mediaType.toString();
assertThat(result).doesNotContain("\r");
}
}
2 changes: 1 addition & 1 deletion guava/src/com/google/common/net/MediaType.java
Original file line number Diff line number Diff line change
Expand Up @@ -1255,7 +1255,7 @@ private static String escapeAndQuote(String value) {
StringBuilder escaped = new StringBuilder(value.length() + 16).append('"');
for (int i = 0; i < value.length(); i++) {
char ch = value.charAt(i);
if (ch == '\r' || ch == '\\' || ch == '"') {
if (ch == '\r' || ch == '\n' || ch == '\\' || ch == '"') {
escaped.append('\\');
}
escaped.append(ch);
Expand Down