Build failed in Jenkins: ManifoldCF ยป ManifoldCF-ant #58

2022-07-19 Thread Apache Jenkins Server
See Changes: [Julien Massiera] CONNECTORS-1721: Confluence v6 does not distinguish 404 errors -- [...truncated 620.63 KB...] webapp-api-service:

[jira] [Commented] (CONNECTORS-1722) remove xalan dependency due to it being end of life

2022-07-19 Thread Karl Wright (Jira)
[ https://issues.apache.org/jira/browse/CONNECTORS-1722?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17568746#comment-17568746 ] Karl Wright commented on CONNECTORS-1722: - Xalan is a downstream dependency of many

[jira] [Created] (CONNECTORS-1722) remove xalan dependency due to it being end of life

2022-07-19 Thread PJ Fanning (Jira)
PJ Fanning created CONNECTORS-1722: -- Summary: remove xalan dependency due to it being end of life Key: CONNECTORS-1722 URL: https://issues.apache.org/jira/browse/CONNECTORS-1722 Project: ManifoldCF

[jira] [Resolved] (CONNECTORS-1721) Confluence v6 does not distinguish 404 errors

2022-07-19 Thread Julien Massiera (Jira)
[ https://issues.apache.org/jira/browse/CONNECTORS-1721?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Julien Massiera resolved CONNECTORS-1721. - Fix Version/s: ManifoldCF 2.23 Resolution: Fixed r1902854 >

[jira] [Created] (CONNECTORS-1721) Confluence v6 does not distinguish 404 errors

2022-07-19 Thread Julien Massiera (Jira)
Julien Massiera created CONNECTORS-1721: --- Summary: Confluence v6 does not distinguish 404 errors Key: CONNECTORS-1721 URL: https://issues.apache.org/jira/browse/CONNECTORS-1721 Project:

Re: Vulnerable log4j Versions

2022-07-19 Thread Karl Wright
We updated log4j four times in December/January. The first two times seemed warranted, although limited even then because the UI and API for an ManifoldCF instance are not ever available on the open internet. The last two were a stretch to think they could cause any problems in our environment,

Vulnerable log4j Versions

2022-07-19 Thread Wolfinger Uwe
We just started an upgrade to version 2.22.1 and noticed, that still vulnerable log4j version are present in the distribution package, e.g.: apache-manifoldcf-2.22.1\lib\log4j-api-2.15.0.jar apache-manifoldcf-2.22.1\web\war\mcf-authority-service\WEB-INF\lib\log4j-api-2.15.0.jar According to