[jira] [Closed] (STR-3222) Regarding Struts Vulnerability Remote Code Execution when deserializing XML payloads - CVE-2017-9805

2017-09-06 Thread Fazith (JIRA)
[ https://issues.apache.org/jira/browse/STR-3222?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Fazith closed STR-3222. --- Resolution: Done Got an update from Struts Security team that 1.2.x is not impacted by this Vulnerability. >

[jira] [Comment Edited] (WW-4849) ObjectFactory constructor signature change breaks extensions

2017-09-06 Thread Mitth'raw'nuruodo (JIRA)
[ https://issues.apache.org/jira/browse/WW-4849?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=16156121#comment-16156121 ] Mitth'raw'nuruodo edited comment on WW-4849 at 9/6/17 10:31 PM:

[jira] [Comment Edited] (WW-4849) ObjectFactory constructor signature change breaks extensions

2017-09-06 Thread Mitth'raw'nuruodo (JIRA)
[ https://issues.apache.org/jira/browse/WW-4849?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=16156121#comment-16156121 ] Mitth'raw'nuruodo edited comment on WW-4849 at 9/6/17 10:30 PM:

[jira] [Comment Edited] (WW-4849) ObjectFactory constructor signature change breaks extensions

2017-09-06 Thread Mitth'raw'nuruodo (JIRA)
[ https://issues.apache.org/jira/browse/WW-4849?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=16156121#comment-16156121 ] Mitth'raw'nuruodo edited comment on WW-4849 at 9/6/17 10:28 PM:

[jira] [Commented] (WW-4849) ObjectFactory constructor signature change breaks extensions

2017-09-06 Thread Mitth'raw'nuruodo (JIRA)
[ https://issues.apache.org/jira/browse/WW-4849?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=16156121#comment-16156121 ] Mitth'raw'nuruodo commented on WW-4849: --- [~aleksandr-m] I'm not sure how much of your previous comment

[jira] [Updated] (WW-4851) Upgrade to Log4j2 2.9.0

2017-09-06 Thread Stefaan Dutry (JIRA)
[ https://issues.apache.org/jira/browse/WW-4851?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Stefaan Dutry updated WW-4851: -- Fix Version/s: 2.5.14 > Upgrade to Log4j2 2.9.0 > --- > > Key: WW-4851

[jira] [Commented] (WW-4851) Upgrade to Log4j2 2.9.0

2017-09-06 Thread ASF GitHub Bot (JIRA)
[ https://issues.apache.org/jira/browse/WW-4851?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=16155842#comment-16155842 ] ASF GitHub Bot commented on WW-4851: GitHub user sdutry opened a pull request:

[jira] [Created] (WW-4851) Upgrade to Log4j2 2.9.0

2017-09-06 Thread Stefaan Dutry (JIRA)
Stefaan Dutry created WW-4851: - Summary: Upgrade to Log4j2 2.9.0 Key: WW-4851 URL: https://issues.apache.org/jira/browse/WW-4851 Project: Struts 2 Issue Type: Dependency Reporter:

[jira] [Comment Edited] (WW-4848) The if test can accidently incorrectly assign a new value to an object

2017-09-06 Thread Yasser Zamani (JIRA)
[ https://issues.apache.org/jira/browse/WW-4848?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=16155617#comment-16155617 ] Yasser Zamani edited comment on WW-4848 at 9/6/17 5:26 PM: --- [~lukaszlenart], five

[jira] [Commented] (WW-4848) The if test can accidently incorrectly assign a new value to an object

2017-09-06 Thread Yasser Zamani (JIRA)
[ https://issues.apache.org/jira/browse/WW-4848?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=16155735#comment-16155735 ] Yasser Zamani commented on WW-4848: --- [~aleksandr-m] yes you're right and I was aware but forgot in my above

[jira] [Commented] (WW-4848) The if test can accidently incorrectly assign a new value to an object

2017-09-06 Thread Aleksandr Mashchenko (JIRA)
[ https://issues.apache.org/jira/browse/WW-4848?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=16155649#comment-16155649 ] Aleksandr Mashchenko commented on WW-4848: -- It is an expression. It can be used in the other tags

[jira] [Commented] (WW-4849) ObjectFactory constructor signature change breaks extensions

2017-09-06 Thread Aleksandr Mashchenko (JIRA)
[ https://issues.apache.org/jira/browse/WW-4849?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=16155643#comment-16155643 ] Aleksandr Mashchenko commented on WW-4849: -- _to ensure that a container can only be injected once_

[jira] [Commented] (WW-4848) The if test can accidently incorrectly assign a new value to an object

2017-09-06 Thread Yasser Zamani (JIRA)
[ https://issues.apache.org/jira/browse/WW-4848?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=16155617#comment-16155617 ] Yasser Zamani commented on WW-4848: --- [~lukaszlenart], five days ago I researched what we can do with this

[jira] [Commented] (WW-4846) Not able to convert Spring object to the JSON response

2017-09-06 Thread Hudson (JIRA)
[ https://issues.apache.org/jira/browse/WW-4846?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=16155146#comment-16155146 ] Hudson commented on WW-4846: SUCCESS: Integrated in Jenkins build Struts-master-JDK7 #25 (See

[jira] [Commented] (WW-4843) DefaultUrlHelper().buildUrl() not outputting port when used as parameter

2017-09-06 Thread Hudson (JIRA)
[ https://issues.apache.org/jira/browse/WW-4843?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=16155145#comment-16155145 ] Hudson commented on WW-4843: SUCCESS: Integrated in Jenkins build Struts-master-JDK7 #25 (See

[jira] [Commented] (WW-4846) Not able to convert Spring object to the JSON response

2017-09-06 Thread ASF subversion and git services (JIRA)
[ https://issues.apache.org/jira/browse/WW-4846?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=16155108#comment-16155108 ] ASF subversion and git services commented on WW-4846: - Commit

[jira] [Resolved] (WW-4846) Not able to convert Spring object to the JSON response

2017-09-06 Thread Lukasz Lenart (JIRA)
[ https://issues.apache.org/jira/browse/WW-4846?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Lukasz Lenart resolved WW-4846. --- Resolution: Fixed PR got merged, thanks! > Not able to convert Spring object to the JSON response >

[jira] [Commented] (WW-4846) Not able to convert Spring object to the JSON response

2017-09-06 Thread ASF subversion and git services (JIRA)
[ https://issues.apache.org/jira/browse/WW-4846?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=16155109#comment-16155109 ] ASF subversion and git services commented on WW-4846: - Commit

[jira] [Commented] (WW-4846) Not able to convert Spring object to the JSON response

2017-09-06 Thread ASF GitHub Bot (JIRA)
[ https://issues.apache.org/jira/browse/WW-4846?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=16155110#comment-16155110 ] ASF GitHub Bot commented on WW-4846: Github user asfgit closed the pull request at:

[jira] [Commented] (WW-4846) Not able to convert Spring object to the JSON response

2017-09-06 Thread ASF subversion and git services (JIRA)
[ https://issues.apache.org/jira/browse/WW-4846?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=16155107#comment-16155107 ] ASF subversion and git services commented on WW-4846: - Commit

[jira] [Commented] (WW-4850) FreeMarker version is rather old

2017-09-06 Thread Hudson (JIRA)
[ https://issues.apache.org/jira/browse/WW-4850?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=16155095#comment-16155095 ] Hudson commented on WW-4850: SUCCESS: Integrated in Jenkins build Struts-master-JDK7 #24 (See

[jira] [Resolved] (WW-4843) DefaultUrlHelper().buildUrl() not outputting port when used as parameter

2017-09-06 Thread Lukasz Lenart (JIRA)
[ https://issues.apache.org/jira/browse/WW-4843?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Lukasz Lenart resolved WW-4843. --- Resolution: Fixed Assignee: Lukasz Lenart PR got merged, thanks! > DefaultUrlHelper().buildUrl()

[jira] [Commented] (WW-4843) DefaultUrlHelper().buildUrl() not outputting port when used as parameter

2017-09-06 Thread ASF subversion and git services (JIRA)
[ https://issues.apache.org/jira/browse/WW-4843?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=16155088#comment-16155088 ] ASF subversion and git services commented on WW-4843: - Commit

[jira] [Commented] (WW-4843) DefaultUrlHelper().buildUrl() not outputting port when used as parameter

2017-09-06 Thread ASF GitHub Bot (JIRA)
[ https://issues.apache.org/jira/browse/WW-4843?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=16155090#comment-16155090 ] ASF GitHub Bot commented on WW-4843: Github user asfgit closed the pull request at:

[jira] [Commented] (WW-4843) DefaultUrlHelper().buildUrl() not outputting port when used as parameter

2017-09-06 Thread ASF subversion and git services (JIRA)
[ https://issues.apache.org/jira/browse/WW-4843?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=16155089#comment-16155089 ] ASF subversion and git services commented on WW-4843: - Commit

[jira] [Updated] (WW-4843) DefaultUrlHelper().buildUrl() not outputting port when used as parameter

2017-09-06 Thread Lukasz Lenart (JIRA)
[ https://issues.apache.org/jira/browse/WW-4843?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Lukasz Lenart updated WW-4843: -- Fix Version/s: (was: 2.6) 2.5.14 > DefaultUrlHelper().buildUrl() not outputting

[jira] [Resolved] (WW-4850) FreeMarker version is rather old

2017-09-06 Thread Lukasz Lenart (JIRA)
[ https://issues.apache.org/jira/browse/WW-4850?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Lukasz Lenart resolved WW-4850. --- Resolution: Fixed Assignee: Lukasz Lenart > FreeMarker version is rather old >

[jira] [Commented] (WW-4850) FreeMarker version is rather old

2017-09-06 Thread ASF subversion and git services (JIRA)
[ https://issues.apache.org/jira/browse/WW-4850?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=16155057#comment-16155057 ] ASF subversion and git services commented on WW-4850: - Commit

[jira] [Commented] (WW-4850) FreeMarker version is rather old

2017-09-06 Thread Lukasz Lenart (JIRA)
[ https://issues.apache.org/jira/browse/WW-4850?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=16155049#comment-16155049 ] Lukasz Lenart commented on WW-4850: --- I though the {{-incubating}} means a BETA in this case, thanks for

[jira] [Updated] (WW-4850) FreeMarker version is rather old

2017-09-06 Thread Lukasz Lenart (JIRA)
[ https://issues.apache.org/jira/browse/WW-4850?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Lukasz Lenart updated WW-4850: -- Fix Version/s: 2.5.14 > FreeMarker version is rather old > > >

[jira] [Created] (WW-4850) FreeMarker version is rather old

2017-09-06 Thread Daniel Dekany (JIRA)
Daniel Dekany created WW-4850: - Summary: FreeMarker version is rather old Key: WW-4850 URL: https://issues.apache.org/jira/browse/WW-4850 Project: Struts 2 Issue Type: Dependency Affects

[jira] [Commented] (WW-4849) ObjectFactory constructor signature change breaks extensions

2017-09-06 Thread Lukasz Lenart (JIRA)
[ https://issues.apache.org/jira/browse/WW-4849?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=16154882#comment-16154882 ] Lukasz Lenart commented on WW-4849: --- Sorry, I meant to fix the vulnerability reported in S2-052 you do not

[jira] [Updated] (WW-4848) The if test can accidently incorrectly assign a new value to an object

2017-09-06 Thread Lukasz Lenart (JIRA)
[ https://issues.apache.org/jira/browse/WW-4848?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Lukasz Lenart updated WW-4848: -- Fix Version/s: (was: 2.5.x) 2.5.14 > The if test can accidently incorrectly assign

[jira] [Commented] (WW-4849) ObjectFactory constructor signature change breaks extensions

2017-09-06 Thread Mitth'raw'nuruodo (JIRA)
[ https://issues.apache.org/jira/browse/WW-4849?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=16154858#comment-16154858 ] Mitth'raw'nuruodo commented on WW-4849: --- Sorry, I don't think I understand your reply properly. "just

[jira] [Commented] (WW-4848) The if test can accidently incorrectly assign a new value to an object

2017-09-06 Thread Lukasz Lenart (JIRA)
[ https://issues.apache.org/jira/browse/WW-4848?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=16154857#comment-16154857 ] Lukasz Lenart commented on WW-4848: --- It's rather unsolvable as this is a proper expression which returns a

[jira] [Updated] (WW-4846) Not able to convert Spring object to the JSON response

2017-09-06 Thread Lukasz Lenart (JIRA)
[ https://issues.apache.org/jira/browse/WW-4846?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Lukasz Lenart updated WW-4846: -- Fix Version/s: (was: 2.5.x) > Not able to convert Spring object to the JSON response >

[jira] [Updated] (WW-4034) Allow to use custom JSONwriter

2017-09-06 Thread Lukasz Lenart (JIRA)
[ https://issues.apache.org/jira/browse/WW-4034?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Lukasz Lenart updated WW-4034: -- Fix Version/s: 2.5.14 > Allow to use custom JSONwriter > -- > >

[jira] [Updated] (WW-4846) Not able to convert Spring object to the JSON response

2017-09-06 Thread Lukasz Lenart (JIRA)
[ https://issues.apache.org/jira/browse/WW-4846?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Lukasz Lenart updated WW-4846: -- Fix Version/s: 2.5.14 > Not able to convert Spring object to the JSON response >

[jira] [Updated] (WW-4849) ObjectFactory constructor signature change breaks extensions

2017-09-06 Thread Lukasz Lenart (JIRA)
[ https://issues.apache.org/jira/browse/WW-4849?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Lukasz Lenart updated WW-4849: -- Fix Version/s: 2.5.14 > ObjectFactory constructor signature change breaks extensions >