From c0dfacbf6c9cae7c0bce2999d01d7dbec13294cf Mon Sep 17 00:00:00 2001 From: Steve Springett Date: Fri, 10 Nov 2017 16:24:50 -0600 Subject: [PATCH] URL encoding double quotes passed in to Maven Central search API #978 --- .../org/owasp/dependencycheck/data/central/CentralSearch.java | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/dependency-check-core/src/main/java/org/owasp/dependencycheck/data/central/CentralSearch.java b/dependency-check-core/src/main/java/org/owasp/dependencycheck/data/central/CentralSearch.java index 6b648eabf..3575d76e0 100644 --- a/dependency-check-core/src/main/java/org/owasp/dependencycheck/data/central/CentralSearch.java +++ b/dependency-check-core/src/main/java/org/owasp/dependencycheck/data/central/CentralSearch.java @@ -108,7 +108,7 @@ public class CentralSearch { throw new IllegalArgumentException("Invalid SHA1 format"); } List result = null; - final URL url = new URL(String.format("%s?q=1:\"%s\"&wt=xml", rootURL, sha1)); + final URL url = new URL(String.format("%s?q=1:%%22%s%%22&wt=xml", rootURL, sha1)); LOGGER.debug("Searching Central url {}", url);