New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
[WFLY-16771] Remove bcel from jboss/xalan-j binaries (Fix CVE-2022-34… #7
Conversation
Put a hold on this; I got test failures with it. |
0501c66
to
609dbc6
Compare
For example: | ||
|
||
export CLASSPATH=~/.m2/repository/org/jboss/spec/javax/ejb/jboss-ejb-api_3.2_spec/2.0.0.Final/jboss-ejb-api_3.2_spec-2.0.0.Final.jar: \ | ||
~/.m2/repository/org/jboss/spec/javax/servlet/jboss-servlet-api_4.0_spec/2.0.0.Final/jboss-servlet-api_4.0_spec-2.0.0.Final.jar |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
I happen to have javax.servlet api in:
~/.m2/repository/javax/servlet/javax.servlet-api/3.1.0/javax.servlet-api-3.1.0.jar
~/.m2/repository/javax/servlet/javax.servlet-api/4.0.1/javax.servlet-api-4.0.1.jar
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Everyone will have different jars I'm sure, especially if they occasionally delete their maven repo. No change needed really.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
+1.
I went with the spec fork GAVs as the example just because it's more likely a typical WildFly dev would have those vs having the javax.* Eclipse artifacts.
Thanks, will wait. |
…:xalan binary (Fix CVE-2022-34169) Change the TransformerFactory to one that does not require BCEL
609dbc6
to
f5fb279
Compare
@@ -1 +1 @@ | |||
org.apache.xalan.xsltc.trax.TransformerFactoryImpl | |||
org.apache.xalan.processor.TransformerFactoryImpl |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Note this change, which I believe means a change in the default TransformerFactory for WF users. (I could be wrong.) The new value here is the one EAP has been using for many years. The existing value uses BCEL, which is not present in the xalan-j.jar that EAP ships.
@scottmarlow The test issues I mentioned previously are resolved. |
…169)
https://issues.redhat.com/browse/WFLY-16771
Also https://issues.redhat.com/browse/WFLY-16782