Re: Recent Apache Commons text CVE

2022-10-24 Thread Colm O hEigeartaigh
Thanks Francesco! Colm. On Mon, Oct 24, 2022 at 4:08 PM Francesco Chicchiriccò wrote: > > Hi Colm, > that class is used exclusively for the db content bootstrap process, which > is run only on empty database. > The input is given through the Domain Content XML file (typically, >

Re: Recent Apache Commons text CVE

2022-10-24 Thread Francesco Chicchiriccò
Hi Colm, that class is used exclusively for the db content bootstrap process, which is run only on empty database. The input is given through the Domain Content XML file (typically, MasterContent.xml), which can be configured to be loaded either from classpath or conf.dir. Nevertheless, the

Recent Apache Commons text CVE

2022-10-24 Thread Colm O hEigeartaigh
Hi, Regarding the recent Apache Commons Text advisory (https://blogs.apache.org/security/entry/cve-2022-42889), Syncope uses the StringSubstitutor API here: