Bug 547736 - Update Xerces Java version 2.12
Summary: Update Xerces Java version 2.12
Status: NEW
Alias: None
Product: Orbit
Classification: Tools
Component: bundles (show other bugs)
Version: unspecified   Edit
Hardware: All All
: P3 normal with 3 votes (vote)
Target Milestone: ---   Edit
Assignee: Orbit Bundles CLA
QA Contact:
URL:
Whiteboard:
Keywords:
: 549827 565547 (view as bug list)
Depends on:
Blocks: 549343 339917
  Show dependency tree
 
Reported: 2019-05-28 09:29 EDT by Nitin Dahyabhai CLA
Modified: 2021-05-05 11:22 EDT (History)
5 users (show)

See Also:


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Nitin Dahyabhai CLA 2019-05-28 09:29:54 EDT
Current offering is a build of Xerces 2.9. I'd like one for 2.12, similarly without the embedded jar files of the original download.

Changelog: https://xerces.apache.org/xerces2-j/releases.html

https://dev.eclipse.org/ipzilla/show_bug.cgi?id=1148
https://dev.eclipse.org/ipzilla/show_bug.cgi?id=16951
https://dev.eclipse.org/ipzilla/show_bug.cgi?id=17773
Comment 1 Nitin Dahyabhai CLA 2019-07-17 20:37:20 EDT
Altering severity due to the StackOverflowError, reported by one of our users, that's already fixed in newer releases.
Comment 2 Dawid Pakula CLA 2020-01-10 07:21:21 EST
It's also required for common XXE vulnerability fix: support for XMLConstants.ACCESS_EXTERNAL_DTD and XMLConstants.ACCESS_EXTERNAL_SCHEMA

https://www.owasp.org/index.php/Top_10-2017_A4-XML_External_Entities_(XXE)
http://cwe.mitre.org/data/definitions/611.html
http://cwe.mitre.org/data/definitions/827.html
Comment 3 Dawid Pakula CLA 2020-01-10 08:48:24 EST
There is also bug 549827
As I see also javax.xml should be updated to 1.4.01

Can any Orbit commiter start IP process?
Comment 4 Roland Grunberg CLA 2020-08-21 10:31:59 EDT
*** Bug 549827 has been marked as a duplicate of this bug. ***
Comment 5 Roland Grunberg CLA 2020-08-21 10:32:22 EDT
*** Bug 565547 has been marked as a duplicate of this bug. ***
Comment 6 Martin D'Aloia CLA 2021-05-05 11:22:08 EDT
I think that this bug could be closed now.
Since Orbit R20210223232630 for 2021-03 Xerces 2.12.1 is provided.

https://download.eclipse.org/tools/orbit/downloads/drops/R20210223232630/repository