1.7.x backport for [SecureUberspector should block methods on ClassLoader and subclasses]

2021-03-22 Thread Cesar Hernandez
Hi all, I opened https://issues.apache.org/jira/browse/VELOCITY-941 along with the Pull Request https://github.com/apache/velocity-engine/pull/21 to accomplish the backport of the patch applied to master via https://issues.apache.org/jira/browse/VELOCITY-931 Hope the backport makes sense since th

[GitHub] [velocity-engine] cesarhernandezgt commented on pull request #16: Velocity 931 update secure classlist

2021-03-22 Thread GitBox
cesarhernandezgt commented on pull request #16: URL: https://github.com/apache/velocity-engine/pull/16#issuecomment-804596546 @lishuochuan @arkanovicz Hello, I created https://issues.apache.org/jira/browse/VELOCITY-941 with the backport to 1.7.x branch. I basically cherry-pick the ch

[jira] [Updated] (VELOCITY-941) 1.7.x backport for SecureUberspector should block methods on ClassLoader and subclasses

2021-03-22 Thread Cesar Hernandez (Jira)
[ https://issues.apache.org/jira/browse/VELOCITY-941?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Cesar Hernandez updated VELOCITY-941: - Description: This is a backport for [https://github.com/apache/velocity-engine/tree/1.7

[jira] [Updated] (VELOCITY-941) 1.7.x backport for SecureUberspector should block methods on ClassLoader and subclasses

2021-03-22 Thread Cesar Hernandez (Jira)
[ https://issues.apache.org/jira/browse/VELOCITY-941?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Cesar Hernandez updated VELOCITY-941: - Description: This is a backport for [https://github.com/apache/velocity-engine/tree/1.7

[jira] [Updated] (VELOCITY-941) 1.7.x backport for SecureUberspector should block methods on ClassLoader and subclasses

2021-03-22 Thread Cesar Hernandez (Jira)
[ https://issues.apache.org/jira/browse/VELOCITY-941?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Cesar Hernandez updated VELOCITY-941: - Description: This is a backport for [https://github.com/apache/velocity-engine/tree/1.7

[jira] [Updated] (VELOCITY-941) 1.7.x backport for SecureUberspector should block methods on ClassLoader and subclasses

2021-03-22 Thread Cesar Hernandez (Jira)
[ https://issues.apache.org/jira/browse/VELOCITY-941?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Cesar Hernandez updated VELOCITY-941: - Fix Version/s: (was: 2.3) 1.7.x > 1.7.x backport for SecureUbers

[jira] [Created] (VELOCITY-941) 1.7.x backport for SecureUberspector should block methods on ClassLoader and subclasses

2021-03-22 Thread Cesar Hernandez (Jira)
Cesar Hernandez created VELOCITY-941: Summary: 1.7.x backport for SecureUberspector should block methods on ClassLoader and subclasses Key: VELOCITY-941 URL: https://issues.apache.org/jira/browse/VELOCITY-941

[GitHub] [velocity-engine] cesarhernandezgt commented on pull request #21: [Backport] Velocity 931 update secure classlist

2021-03-22 Thread GitBox
cesarhernandezgt commented on pull request #21: URL: https://github.com/apache/velocity-engine/pull/21#issuecomment-804545676 depends on #22 -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the