-
Notifications
You must be signed in to change notification settings - Fork 130
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Velocity 931 update secure classlist #16
Velocity 931 update secure classlist #16
Conversation
Looks good to me. |
hi @wglasshusain @nbubna , can we get this merged so the new version can be released? Thanks! |
hi @wglasshusain @nbubna, any update on this? |
velocity-engine-core/src/test/java/org/apache/velocity/test/SecureIntrospectionTestCase.java
Show resolved
Hide resolved
May I know any plan to merge the fix to velocity-1.7? |
There is no plan whatsoever to update 1.7. Look. Velocity 1.7 was released in 2010. That's more than ten years ago. You can't seriously ask for us to maintain ten years old code. Feel free to integrate the patch yourself, though. |
@lishuochuan @arkanovicz |
apache/velocity-engine#16 to SecureIntrospectorImpl to resolve CVE-2020-13936
apache/velocity-engine#16 to SecureIntrospectorImpl to resolve CVE-2020-13936
apache/velocity-engine#16 to SecureIntrospectorImpl to resolve CVE-2020-13936
apache/velocity-engine#16 to SecureIntrospectorImpl to resolve CVE-2020-13936
apache/velocity-engine#16 to SecureIntrospectorImpl to resolve CVE-2020-13936
No description provided.