[jira] [Resolved] (SLING-11658) sling remote code execute

2022-11-02 Thread Robert Munteanu (Jira)
[ https://issues.apache.org/jira/browse/SLING-11658?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Robert Munteanu resolved SLING-11658. - Resolution: Invalid Thank you for your report. In the future, please report security

[GitHub] [sling-org-apache-sling-resourceresolver] reschke commented on pull request #82: SLING-11581: use keyset pagination for vanity path query

2022-11-02 Thread GitBox
reschke commented on PR #82: URL: https://github.com/apache/sling-org-apache-sling-resourceresolver/pull/82#issuecomment-1299882688 will look at improving test coverage... -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and

[GitHub] [sling-org-apache-sling-resourceresolver] cziegeler commented on a diff in pull request #85: SLING-11604: Async VanityPathInitializer should log when completed

2022-11-02 Thread GitBox
cziegeler commented on code in PR #85: URL: https://github.com/apache/sling-org-apache-sling-resourceresolver/pull/85#discussion_r1011234227 ## src/main/java/org/apache/sling/resourceresolver/impl/mapping/MapEntries.java: ## @@ -341,7 +342,8 @@ private void execute() {

[GitHub] [sling-org-apache-sling-jcr-resource] anchela commented on a diff in pull request #38: SLING-11654 implement AccessMetrics

2022-11-02 Thread GitBox
anchela commented on code in PR #38: URL: https://github.com/apache/sling-org-apache-sling-jcr-resource/pull/38#discussion_r1011301674 ## src/main/java/org/apache/sling/jcr/resource/internal/helper/AccessMetrics.java: ## @@ -0,0 +1,126 @@ +/* + * Licensed to the Apache

[GitHub] [sling-org-apache-sling-resourceresolver] sonarcloud[bot] commented on pull request #85: SLING-11604: Async VanityPathInitializer should log when completed

2022-11-02 Thread GitBox
sonarcloud[bot] commented on PR #85: URL: https://github.com/apache/sling-org-apache-sling-resourceresolver/pull/85#issuecomment-1299700133 Kudos, SonarCloud Quality Gate passed! [![Quality Gate

[GitHub] [sling-org-apache-sling-resourceresolver] sonarcloud[bot] commented on pull request #86: SLING-11659: Resource Resolver - remove dead test code remove dead test code related to persisted bloo

2022-11-02 Thread GitBox
sonarcloud[bot] commented on PR #86: URL: https://github.com/apache/sling-org-apache-sling-resourceresolver/pull/86#issuecomment-1300017659 Kudos, SonarCloud Quality Gate passed! [![Quality Gate

[jira] [Commented] (SLING-11507) Field injection should not inject static fields

2022-11-02 Thread Carsten Ziegeler (Jira)
[ https://issues.apache.org/jira/browse/SLING-11507?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17627496#comment-17627496 ] Carsten Ziegeler commented on SLING-11507: -- [~rombert] True, a static method could be written

[jira] [Created] (SLING-11659) ResourceResolver: remove dead test code related to persisted bloom filter

2022-11-02 Thread Julian Reschke (Jira)
Julian Reschke created SLING-11659: -- Summary: ResourceResolver: remove dead test code related to persisted bloom filter Key: SLING-11659 URL: https://issues.apache.org/jira/browse/SLING-11659

[jira] [Assigned] (SLING-11604) Async VanityPathInitializer should log when completed

2022-11-02 Thread Carsten Ziegeler (Jira)
[ https://issues.apache.org/jira/browse/SLING-11604?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Carsten Ziegeler reassigned SLING-11604: Assignee: Carsten Ziegeler > Async VanityPathInitializer should log when

[jira] [Updated] (SLING-11604) Async VanityPathInitializer should log when completed

2022-11-02 Thread Carsten Ziegeler (Jira)
[ https://issues.apache.org/jira/browse/SLING-11604?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Carsten Ziegeler updated SLING-11604: - Fix Version/s: Resource Resolver 1.10.2 > Async VanityPathInitializer should log when

[GitHub] [sling-org-apache-sling-resourceresolver] cziegeler merged pull request #85: SLING-11604: Async VanityPathInitializer should log when completed

2022-11-02 Thread GitBox
cziegeler merged PR #85: URL: https://github.com/apache/sling-org-apache-sling-resourceresolver/pull/85 -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail:

[jira] [Comment Edited] (SLING-11507) Field injection should not inject static fields

2022-11-02 Thread Carsten Ziegeler (Jira)
[ https://issues.apache.org/jira/browse/SLING-11507?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17627496#comment-17627496 ] Carsten Ziegeler edited comment on SLING-11507 at 11/2/22 7:21 AM: ---

[jira] [Resolved] (SLING-11604) Async VanityPathInitializer should log when completed

2022-11-02 Thread Carsten Ziegeler (Jira)
[ https://issues.apache.org/jira/browse/SLING-11604?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Carsten Ziegeler resolved SLING-11604. -- Resolution: Fixed > Async VanityPathInitializer should log when completed >

[GitHub] [sling-org-apache-sling-resourceresolver] sonarcloud[bot] commented on pull request #82: SLING-11581: use keyset pagination for vanity path query

2022-11-02 Thread GitBox
sonarcloud[bot] commented on PR #82: URL: https://github.com/apache/sling-org-apache-sling-resourceresolver/pull/82#issuecomment-1299870073 SonarCloud Quality Gate failed. [![Quality Gate

[GitHub] [sling-org-apache-sling-resourceresolver] sonarcloud[bot] commented on pull request #86: SLING-11659: Resource Resolver - remove dead test code remove dead test code related to persisted bloo

2022-11-02 Thread GitBox
sonarcloud[bot] commented on PR #86: URL: https://github.com/apache/sling-org-apache-sling-resourceresolver/pull/86#issuecomment-1300020182 Kudos, SonarCloud Quality Gate passed! [![Quality Gate

CVE-2022-43670: Apache Sling App CMS: XSS in Sling CMS Reference App Taxonomy Path

2022-11-02 Thread Dan Klco
Severity: low Description: An improper neutralization of input during web page generation ('Cross-site Scripting') [CWE-79] vulnerability in Sling App CMS version 1.1.0 and prior may allow an authenticated remote attacker to perform a reflected cross site scripting (XSS) attack in the

[jira] [Closed] (SLING-11622) Unexpected input may cause xss risk in Taxonomy

2022-11-02 Thread Dan Klco (Jira)
[ https://issues.apache.org/jira/browse/SLING-11622?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Dan Klco closed SLING-11622. > Unexpected input may cause xss risk in Taxonomy > --- > >

[jira] [Resolved] (SLING-11622) Unexpected input may cause xss risk in Taxonomy

2022-11-02 Thread Dan Klco (Jira)
[ https://issues.apache.org/jira/browse/SLING-11622?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Dan Klco resolved SLING-11622. -- Fix Version/s: App CMS 1.1.2 Assignee: Dan Klco Resolution: Fixed > Unexpected input

[jira] [Resolved] (SLING-9942) Retrieve Sling Content with Sling API

2022-11-02 Thread Dan Klco (Jira)
[ https://issues.apache.org/jira/browse/SLING-9942?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Dan Klco resolved SLING-9942. - Resolution: Not A Problem Hi [~preeth07], this is not a support forum, I would suggest reviewing:

[jira] [Closed] (SLING-9942) Retrieve Sling Content with Sling API

2022-11-02 Thread Dan Klco (Jira)
[ https://issues.apache.org/jira/browse/SLING-9942?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Dan Klco closed SLING-9942. --- > Retrieve Sling Content with Sling API > -- > > Key:

[jira] [Resolved] (SLING-7900) App CMS UI enhancements

2022-11-02 Thread Dan Klco (Jira)
[ https://issues.apache.org/jira/browse/SLING-7900?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Dan Klco resolved SLING-7900. - Resolution: Won't Fix > App CMS UI enhancements > --- > > Key:

[jira] [Closed] (SLING-7900) App CMS UI enhancements

2022-11-02 Thread Dan Klco (Jira)
[ https://issues.apache.org/jira/browse/SLING-7900?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Dan Klco closed SLING-7900. --- > App CMS UI enhancements > --- > > Key: SLING-7900 > URL:

[GitHub] [sling-org-apache-sling-resourceresolver] sonarcloud[bot] commented on pull request #82: SLING-11581: use keyset pagination for vanity path query

2022-11-02 Thread GitBox
sonarcloud[bot] commented on PR #82: URL: https://github.com/apache/sling-org-apache-sling-resourceresolver/pull/82#issuecomment-1300299861 SonarCloud Quality Gate failed. [![Quality Gate

[jira] [Closed] (SLING-11658) sling remote code execute

2022-11-02 Thread QSec-Team (Jira)
[ https://issues.apache.org/jira/browse/SLING-11658?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] QSec-Team closed SLING-11658. - > sling remote code execute > - > > Key: SLING-11658 >

[GitHub] [sling-org-apache-sling-resourceresolver] cziegeler merged pull request #86: SLING-11659: Resource Resolver - remove dead test code remove dead test code related to persisted bloom filter

2022-11-02 Thread GitBox
cziegeler merged PR #86: URL: https://github.com/apache/sling-org-apache-sling-resourceresolver/pull/86 -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail:

[Jenkins] Sling » Modules » sling-org-apache-sling-starter » master #500 is FIXED

2022-11-02 Thread Apache Jenkins Server
Please see https://ci-builds.apache.org/job/Sling/job/modules/job/sling-org-apache-sling-starter/job/master/500/ for details. No further emails will be sent until the status of the build is changed.

[GitHub] [sling-org-apache-sling-resourceresolver] sonarcloud[bot] commented on pull request #82: SLING-11581: use keyset pagination for vanity path query

2022-11-02 Thread GitBox
sonarcloud[bot] commented on PR #82: URL: https://github.com/apache/sling-org-apache-sling-resourceresolver/pull/82#issuecomment-1300851325 SonarCloud Quality Gate failed. [![Quality Gate

[GitHub] [sling-org-apache-sling-resourceresolver] sonarcloud[bot] commented on pull request #82: SLING-11581: use keyset pagination for vanity path query

2022-11-02 Thread GitBox
sonarcloud[bot] commented on PR #82: URL: https://github.com/apache/sling-org-apache-sling-resourceresolver/pull/82#issuecomment-1300886087 Kudos, SonarCloud Quality Gate passed! [![Quality Gate

[jira] [Created] (SLING-11661) Improve SlingIncludeAttributeTagProcessor

2022-11-02 Thread Oliver Lietz (Jira)
Oliver Lietz created SLING-11661: Summary: Improve SlingIncludeAttributeTagProcessor Key: SLING-11661 URL: https://issues.apache.org/jira/browse/SLING-11661 Project: Sling Issue Type: Task

[jira] [Created] (SLING-11660) Improve IncludeDirective

2022-11-02 Thread Oliver Lietz (Jira)
Oliver Lietz created SLING-11660: Summary: Improve IncludeDirective Key: SLING-11660 URL: https://issues.apache.org/jira/browse/SLING-11660 Project: Sling Issue Type: Task