This is an automated email from the ASF dual-hosted git repository. jleroux pushed a change to branch trunk in repository https://gitbox.apache.org/repos/asf/ofbiz-framework.git.
from de1e9e4 Improved: Convert ShoppingListServices.xml mini lang to groovy (OFBIZ-11602) new 67665d1 Fixed: Found a new XXE (XML External Entity Injection) vulnerability in ArtifactInfo (OFBIZ-12306) new 7a22a2b Fixed: Found a new XXE (XML External Entity Injection) vulnerability in EntityImport (OFBIZ-12304) The 2 revisions listed above as "new" are entirely new to this repository and will be described in separate emails. The revisions listed as "add" were already present in the repository and have only been added to this reference. Summary of changes: .../main/java/org/apache/ofbiz/base/util/UtilURL.java | 2 +- .../java/org/apache/ofbiz/base/util/UtilValidate.java | 18 ++++++++++++++++-- .../groovyScripts/artifactinfo/ArtifactInfo.groovy | 10 +++++++--- .../org/apache/ofbiz/webtools/WebToolsServices.java | 5 +++++ 4 files changed, 29 insertions(+), 6 deletions(-)