This is an automated email from the ASF dual-hosted git repository.
mridulpathak pushed a commit to branch release24.09
in repository https://gitbox.apache.org/repos/asf/ofbiz-framework.git
The following commit(s) were added to refs/heads/release24.09 by this push:
new adc29886fa Bump org.mustangproject:library from 2.8.0 to 2.26.0 (#1803)
adc29886fa is described below
commit adc29886fa08d790665789ed923f27fa79b1026b
Author: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
AuthorDate: Sat Aug 29 15:59:26 2026 +0530
Bump org.mustangproject:library from 2.8.0 to 2.26.0 (#1803)
Bumps
[org.mustangproject:library](https://github.com/ZUGFeRD/mustangproject)
from 2.8.0 to 2.26.0.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/ZUGFeRD/mustangproject/releases">org.mustangproject:library's
releases</a>.</em></p>
<blockquote>
<h2>2.26.0</h2>
<h2>New Features</h2>
<ul>
<li><a
href="https://redirect.github.com/ZUGFeRD/mustangproject/issues/1233">#1233</a>
Add Seller tax representative (BG-11) to CII profiles, excluding
Minimum</li>
<li>Import and Export TaxCurrencyCode (BT-6) and corresponding
TaxTotalAmount (BT-111)</li>
<li><a
href="https://redirect.github.com/ZUGFeRD/mustangproject/issues/1243">#1243</a>
Support TypeCode and ValueMeasure for ApplicableProductCharacteristic on
EXTENDED profile.</li>
</ul>
<h2>Fixes</h2>
<ul>
<li>Upgrade CEN EN16931 Schematron from v1.3.15 to v1.3.16</li>
<li><a
href="https://redirect.github.com/ZUGFeRD/mustangproject/issues/1225">#1225</a>:
fix fluent API for subclasses of TradeTax (Charge, Allowance,
LogisticsServiceCharge)</li>
<li>Modify valid version array in PDFValidator, add "3p0"</li>
<li><a
href="https://redirect.github.com/ZUGFeRD/mustangproject/issues/1228">#1228</a>
Allow import of invoices with a LineTotalAmount having more than 2
decimals. <a
href="https://redirect.github.com/ZUGFeRD/mustangproject/issues/1231">#1231</a></li>
<li><a
href="https://redirect.github.com/ZUGFeRD/mustangproject/issues/1229">#1229</a>
ZF_250 XSDs contain ten dangling schemaLocation references</li>
<li><a
href="https://redirect.github.com/ZUGFeRD/mustangproject/issues/1219">#1219</a>
<a
href="https://redirect.github.com/ZUGFeRD/mustangproject/issues/1223">#1223</a>
<a
href="https://redirect.github.com/ZUGFeRD/mustangproject/issues/1220">#1220</a>
Prevent NPE in Item.enrichProductFromVATBreakdown for VAT category
"O".</li>
<li>Upgrade com.fasterxml.jackson.core to 2.22.2 from 2.22.1</li>
</ul>
<h2>2.25.0</h2>
<h2>Highlights</h2>
<p>Support for ZUGFeRD 2.5.2 (=Factur-X 1.09.2, <a
href="https://redirect.github.com/ZUGFeRD/mustangproject/issues/1216">#1216</a>)
as well as support LogisticsServiceCharges (Zuschläge für Versand &
Verpackung, <a
href="https://redirect.github.com/ZUGFeRD/mustangproject/issues/228">#228</a>)
and fixing VeraPDF Vulnerabilities CVE-2026-54078 and CVE-2026-54079 (<a
href="https://redirect.github.com/ZUGFeRD/mustangproject/issues/1213">#1213</a>)</p>
<h2>Fixes</h2>
<ul>
<li><a
href="https://redirect.github.com/ZUGFeRD/mustangproject/issues/1207">#1207</a>
itemTotalNetAmount is null Exception when validating invoices</li>
<li><a
href="https://redirect.github.com/ZUGFeRD/mustangproject/issues/925">#925</a>
Emit line-level CalculationPercent (BT-138) and BasisAmount (BT-137) for
the EN16931 and XRechnung profiles, using the caller-supplied
Allowance/Charge basis amount.</li>
<li><a
href="https://redirect.github.com/ZUGFeRD/mustangproject/issues/1171">#1171</a>
Removed deprecated methods Item::getAllowances() Item::getCharges() and
their last usage in ZUGFeRD2PullProvider.</li>
<li><a
href="https://redirect.github.com/ZUGFeRD/mustangproject/issues/1174">#1174</a>
Fix UBL AllowanceCharge import, add missing percent/basisAmount aliases,
dropped per-unit-price allowances</li>
<li><a
href="https://redirect.github.com/ZUGFeRD/mustangproject/issues/1163">#1163</a>
Make doRecalculateItemPricesFromLineTotals() use more than the fixed
scale of 4.</li>
<li><a
href="https://redirect.github.com/ZUGFeRD/mustangproject/issues/1162">#1162</a>
Skip the elements "Information" and
"PayeeSpecifiedCreditorFinancialInstitution" for basic
profiles.</li>
<li><a
href="https://redirect.github.com/ZUGFeRD/mustangproject/issues/1134">#1134</a>
Fix: Trade party universal communication id not imported when scheme is
not "email address" (EM) but "electronic address"
(0225).</li>
<li><a
href="https://redirect.github.com/ZUGFeRD/mustangproject/issues/1150">#1150</a>
Remove [D].[M].[Y] after Rechnungsdatum in HTML visualization</li>
<li><a
href="https://redirect.github.com/ZUGFeRD/mustangproject/issues/996">#996</a>
Omit ExemptionReason written to line item level for profile EN16931,
some validators raise a warning or even an error</li>
<li><a
href="https://redirect.github.com/ZUGFeRD/mustangproject/issues/1097">#1097</a>
Invoice importer: LegalOrganization id not imported (wrong node name
'GlobalID' instead of 'ID' used)</li>
<li><a
href="https://redirect.github.com/ZUGFeRD/mustangproject/issues/1151">#1151</a>
'BR-FXEXT-IC-08rev' in ZF 2.5 requires VAT exemption reason text and
code for allowances and charges</li>
<li><a
href="https://redirect.github.com/ZUGFeRD/mustangproject/issues/1145">#1145</a>
Document-level allowance with VAT category O emits RateApplicablePercent
(violates BR-O-06)</li>
<li>add disableArithmeticCheck() / --no-arithmetic-check option to skip
the arithmetic recalculation pass during validation</li>
<li><a
href="https://redirect.github.com/ZUGFeRD/mustangproject/issues/1167">#1167</a>
Upgrade com.fasterxml.jackson.core to 2.22.1 from 2.17.3</li>
<li><a
href="https://redirect.github.com/ZUGFeRD/mustangproject/issues/1186">#1186</a>
Read Item LineTotalAmount from
SpecifiedTradeSettlementLineMonetarySummation</li>
<li><a
href="https://redirect.github.com/ZUGFeRD/mustangproject/issues/976">#976</a>
/ <a
href="https://redirect.github.com/ZUGFeRD/mustangproject/issues/797">#797</a>
InvoiceImport: read ContractReferencedDocument/IssuerAssignedID into
Invoice.contractReferencedDocument</li>
<li><a
href="https://redirect.github.com/ZUGFeRD/mustangproject/issues/987">#987</a>
Show only the matching BIC per IBAN in invoice visualization</li>
<li><a
href="https://redirect.github.com/ZUGFeRD/mustangproject/issues/982">#982</a>
Support TypeCodes 130 and 916 for AdditionalReferencedDocuments</li>
<li><a
href="https://redirect.github.com/ZUGFeRD/mustangproject/issues/1202">#1202</a>
Support IndividualTradeProductInstance with BatchID and
SupplierAssignedSerialID for EXTENDED Profile</li>
<li><a
href="https://redirect.github.com/ZUGFeRD/mustangproject/issues/1205">#1205</a>
Refactoring of Invoice's DocumentReferences.</li>
<li><a
href="https://redirect.github.com/ZUGFeRD/mustangproject/issues/1208">#1208</a>
Prevent NPE when generating XML invoice without issue date.</li>
<li><a
href="https://redirect.github.com/ZUGFeRD/mustangproject/issues/1211">#1211</a>
Change to UBL 2.4 and add commandline option for profile and
customization ID.</li>
<li><a
href="https://redirect.github.com/ZUGFeRD/mustangproject/issues/1212">#1212</a>
Remove deprecated method
IExportableTransaction::getTradeSettlementPayment.</li>
<li><a
href="https://redirect.github.com/ZUGFeRD/mustangproject/issues/1215">#1215</a>
Removed duplicate code in ZUGFeRD2PullProvider, which lead to a
duplicate DirectDebitMandateID.</li>
<li><a
href="https://redirect.github.com/ZUGFeRD/mustangproject/issues/956">#956</a>
Import all SpecifiedTradePaymentTerms blocks, not just the last
one.</li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/ZUGFeRD/mustangproject/blob/master/History.md">org.mustangproject:library's
changelog</a>.</em></p>
<blockquote>
<h1>2.26.0</h1>
<p>2026-08-25</p>
<ul>
<li>Upgrade CEN EN16931 Schematron from v1.3.15 to v1.3.16</li>
<li><a
href="https://redirect.github.com/ZUGFeRD/mustangproject/issues/1233">#1233</a>
Add Seller tax representative (BG-11) to CII profiles, excluding
Minimum</li>
<li>Import and Export TaxCurrencyCode (BT-6) and corresponding
TaxTotalAmount (BT-111)</li>
<li><a
href="https://redirect.github.com/ZUGFeRD/mustangproject/issues/1225">#1225</a>:
fix fluent API for subclasses of TradeTax (Charge, Allowance,
LogisticsServiceCharge)</li>
<li>Modify valid version array in PDFValidator, add "3p0"</li>
<li><a
href="https://redirect.github.com/ZUGFeRD/mustangproject/issues/1228">#1228</a>
Allow import of invoices with a LineTotalAmount having more than 2
decimals. <a
href="https://redirect.github.com/ZUGFeRD/mustangproject/issues/1231">#1231</a></li>
<li><a
href="https://redirect.github.com/ZUGFeRD/mustangproject/issues/1229">#1229</a>
ZF_250 XSDs contain ten dangling schemaLocation references</li>
<li><a
href="https://redirect.github.com/ZUGFeRD/mustangproject/issues/1219">#1219</a>
<a
href="https://redirect.github.com/ZUGFeRD/mustangproject/issues/1223">#1223</a>
<a
href="https://redirect.github.com/ZUGFeRD/mustangproject/issues/1220">#1220</a>
Prevent NPE in Item.enrichProductFromVATBreakdown for VAT category
"O".</li>
<li><a
href="https://redirect.github.com/ZUGFeRD/mustangproject/issues/1243">#1243</a>
Support TypeCode and ValueMeasure for ApplicableProductCharacteristic on
EXTENDED profile.</li>
<li>Upgrade com.fasterxml.jackson.core to 2.22.2 from 2.22.1</li>
</ul>
<h1>2.25.0</h1>
<p>2026-08-04</p>
<ul>
<li><a
href="https://redirect.github.com/ZUGFeRD/mustangproject/issues/1216">#1216</a>
ZUGFeRD 2.5.2 and Factur-X 1.09.2</li>
<li><a
href="https://redirect.github.com/ZUGFeRD/mustangproject/issues/1213">#1213</a>
VeraPDF Vulnerabilities CVE-2026-54078 and CVE-2026-54079</li>
<li><a
href="https://redirect.github.com/ZUGFeRD/mustangproject/issues/1207">#1207</a>
itemTotalNetAmount is null Exception when validating invoices</li>
<li><a
href="https://redirect.github.com/ZUGFeRD/mustangproject/issues/925">#925</a>
Emit line-level CalculationPercent (BT-138) and BasisAmount (BT-137) for
the EN16931 and XRechnung profiles, using the caller-supplied
Allowance/Charge basis amount.</li>
<li><a
href="https://redirect.github.com/ZUGFeRD/mustangproject/issues/1171">#1171</a>
Removed deprecated methods Item::getAllowances() Item::getCharges() and
their last usage in ZUGFeRD2PullProvider.</li>
<li><a
href="https://redirect.github.com/ZUGFeRD/mustangproject/issues/228">#228</a>
Support LogisticsServiceCharges (Zuschläge für Versand &
Verpackung)</li>
<li><a
href="https://redirect.github.com/ZUGFeRD/mustangproject/issues/1174">#1174</a>
Fix UBL AllowanceCharge import, add missing percent/basisAmount aliases,
dropped per-unit-price allowances</li>
<li><a
href="https://redirect.github.com/ZUGFeRD/mustangproject/issues/1163">#1163</a>
Make doRecalculateItemPricesFromLineTotals() use more than the fixed
scale of 4.</li>
<li><a
href="https://redirect.github.com/ZUGFeRD/mustangproject/issues/1162">#1162</a>
Skip the elements "Information" and
"PayeeSpecifiedCreditorFinancialInstitution" for basic
profiles.</li>
<li><a
href="https://redirect.github.com/ZUGFeRD/mustangproject/issues/1134">#1134</a>
Fix: Trade party universal communication id not imported when scheme is
not "email address" (EM) but "electronic address"
(0225).</li>
<li><a
href="https://redirect.github.com/ZUGFeRD/mustangproject/issues/1150">#1150</a>
Remove [D].[M].[Y] after Rechnungsdatum in HTML visualization</li>
<li><a
href="https://redirect.github.com/ZUGFeRD/mustangproject/issues/996">#996</a>
Omit ExemptionReason written to line item level for profile EN16931,
some validators raise a warning or even an error</li>
<li><a
href="https://redirect.github.com/ZUGFeRD/mustangproject/issues/1097">#1097</a>
Invoice importer: LegalOrganization id not imported (wrong node name
'GlobalID' instead of 'ID' used)</li>
<li><a
href="https://redirect.github.com/ZUGFeRD/mustangproject/issues/1151">#1151</a>
'BR-FXEXT-IC-08rev' in ZF 2.5 requires VAT exemption reason text and
code for allowances and charges</li>
<li><a
href="https://redirect.github.com/ZUGFeRD/mustangproject/issues/1145">#1145</a>
Document-level allowance with VAT category O emits RateApplicablePercent
(violates BR-O-06)</li>
<li>add disableArithmeticCheck() / --no-arithmetic-check option to skip
the arithmetic recalculation pass during validation</li>
<li><a
href="https://redirect.github.com/ZUGFeRD/mustangproject/issues/1167">#1167</a>
Upgrade com.fasterxml.jackson.core to 2.22.1 from 2.17.3</li>
<li><a
href="https://redirect.github.com/ZUGFeRD/mustangproject/issues/1186">#1186</a>
Read Item LineTotalAmount from
SpecifiedTradeSettlementLineMonetarySummation</li>
<li><a
href="https://redirect.github.com/ZUGFeRD/mustangproject/issues/976">#976</a>
/ <a
href="https://redirect.github.com/ZUGFeRD/mustangproject/issues/797">#797</a>
InvoiceImport: read ContractReferencedDocument/IssuerAssignedID into
Invoice.contractReferencedDocument</li>
<li><a
href="https://redirect.github.com/ZUGFeRD/mustangproject/issues/987">#987</a>
Show only the matching BIC per IBAN in invoice visualization</li>
<li><a
href="https://redirect.github.com/ZUGFeRD/mustangproject/issues/982">#982</a>
Support TypeCodes 130 and 916 for AdditionalReferencedDocuments</li>
<li><a
href="https://redirect.github.com/ZUGFeRD/mustangproject/issues/1202">#1202</a>
Support IndividualTradeProductInstance with BatchID and
SupplierAssignedSerialID for EXTENDED Profile</li>
<li><a
href="https://redirect.github.com/ZUGFeRD/mustangproject/issues/1205">#1205</a>
Refactoring of Invoice's DocumentReferences.</li>
<li><a
href="https://redirect.github.com/ZUGFeRD/mustangproject/issues/1208">#1208</a>
Prevent NPE when generating XML invoice without issue date.</li>
<li><a
href="https://redirect.github.com/ZUGFeRD/mustangproject/issues/1211">#1211</a>
Change to UBL 2.4 and add commandline option for profile and
customization ID.</li>
<li><a
href="https://redirect.github.com/ZUGFeRD/mustangproject/issues/1212">#1212</a>
Remove deprecated method
IExportableTransaction::getTradeSettlementPayment.</li>
<li><a
href="https://redirect.github.com/ZUGFeRD/mustangproject/issues/1215">#1215</a>
Removed duplicate code in ZUGFeRD2PullProvider, which lead to a
duplicate DirectDebitMandateID.</li>
<li><a
href="https://redirect.github.com/ZUGFeRD/mustangproject/issues/956">#956</a>
Import all SpecifiedTradePaymentTerms blocks, not just the last
one.</li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/ZUGFeRD/mustangproject/commit/6bf5ab9551e2bf5510c012b8b48708e32a8bded1"><code>6bf5ab9</code></a>
updated javadoc</li>
<li><a
href="https://github.com/ZUGFeRD/mustangproject/commit/292a8ce2f891f4be799da669614c85023bd1d58f"><code>292a8ce</code></a>
updated history</li>
<li><a
href="https://github.com/ZUGFeRD/mustangproject/commit/659050bcf13236ab7d73cfdfd3973bf8241dbca1"><code>659050b</code></a>
Upgrade com.fasterxml.jackson.core to 2.22.2 from 2.22.1.</li>
<li><a
href="https://github.com/ZUGFeRD/mustangproject/commit/1a84b38baa51dcace54d99317058f0166203a2b3"><code>1a84b38</code></a>
Fix wrong positioning of ApplicableProductCharacteristic.</li>
<li><a
href="https://github.com/ZUGFeRD/mustangproject/commit/096db40a9806b0b5202028509dff3563efe7fc8c"><code>096db40</code></a>
Remove debug System.out statement.</li>
<li><a
href="https://github.com/ZUGFeRD/mustangproject/commit/2e3e07e3aedce7851f04e5172671718de877dbea"><code>2e3e07e</code></a>
Support TypeCode / ValueMeasure for ApplicableProductCharacteristic on
EXTEND...</li>
<li><a
href="https://github.com/ZUGFeRD/mustangproject/commit/ee907d693656993643493f820d5cb65f723772df"><code>ee907d6</code></a>
Do not import an embedded BG-24 attachment twice</li>
<li><a
href="https://github.com/ZUGFeRD/mustangproject/commit/5576403074721b5fdfc9baa4182f70d490895b23"><code>5576403</code></a>
Use Checktyle also for the test classes, fix checkstyle failures.</li>
<li><a
href="https://github.com/ZUGFeRD/mustangproject/commit/212789adfca5ba518b93a823d6198b2475f94c8c"><code>212789a</code></a>
Set ErrorHandler to SchemaFactory to get validation errors on incorrect
xsd´s.</li>
<li><a
href="https://github.com/ZUGFeRD/mustangproject/commit/7e263a7b403f26cc27b2fa64ed8141633097f2ff"><code>7e263a7</code></a>
upated history</li>
<li>Additional commits viewable in <a
href="https://github.com/ZUGFeRD/mustangproject/compare/core-2.8.0...core-2.26.0">compare
view</a></li>
</ul>
</details>
<br />
[](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)
Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.
[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)
---
<details>
<summary>Dependabot commands and options</summary>
<br />
You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)
</details>
---------
Signed-off-by: dependabot[bot] <[email protected]>
Co-authored-by: dependabot[bot]
<49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Suraj Rajan <[email protected]>
Co-authored-by: Mridul Pathak <[email protected]>
---
dependencies.gradle | 11 ++++++-----
.../java/org/apache/ofbiz/entity/serialize/XmlSerializer.java | 2 +-
.../main/java/org/apache/ofbiz/security/SecuredUpload.java | 4 +++-
3 files changed, 10 insertions(+), 7 deletions(-)
diff --git a/dependencies.gradle b/dependencies.gradle
index 76d4447002..7f9aeb9736 100644
--- a/dependencies.gradle
+++ b/dependencies.gradle
@@ -49,14 +49,15 @@ dependencies {
implementation 'org.apache.logging.log4j:log4j-api:2.26.1' // the API of
log4j 2
implementation 'org.apache.logging.log4j:log4j-core:2.26.1' // Somehow
needed by Buildbot to compile OFBizDynamicThresholdFilter.java
implementation 'org.apache.poi:poi:4.1.2' // poi-ooxml-schemas-5.0.0.pom'.
Received status code 401 from server
- implementation 'org.apache.pdfbox:pdfbox:2.0.37' // 3.0.1 does not compile
+ implementation 'org.apache.pdfbox:pdfbox:3.0.8'
+ implementation 'org.apache.pdfbox:pdfbox-io:3.0.8'
implementation 'org.apache.shiro:shiro-core:1.13.0'
implementation 'org.apache.shiro:shiro-crypto-cipher:2.2.1'
implementation 'org.apache.sshd:sshd-core:2.19.0'
implementation 'org.apache.sshd:sshd-sftp:2.19.0'
- implementation 'org.apache.tika:tika-core:2.9.4'
- implementation 'org.apache.tika:tika-parsers:2.9.4'
- implementation 'org.apache.tika:tika-parser-pdf-module:2.9.4'
+ implementation 'org.apache.tika:tika-core:3.3.2'
+ implementation 'org.apache.tika:tika-parsers:3.3.2'
+ implementation 'org.apache.tika:tika-parser-pdf-module:3.3.2'
implementation 'org.apache.cxf:cxf-rt-frontend-jaxrs:3.6.12' // 4.0.3 does
not compile
implementation 'org.apache.tomcat:tomcat-catalina-ha:9.0.121' // Remember
to change the version number (9 now) in javadoc block if needed.
implementation 'org.apache.tomcat:tomcat-jasper:9.0.121'
@@ -80,7 +81,7 @@ dependencies {
implementation 'org.jdom:jdom:1.1.3' // don't upgrade above 1.1.3, makes a
lot of not obvious and useless complications, see last commits of OFBIZ-12092
for more
implementation 'com.google.re2j:re2j:1.8'
implementation 'xerces:xercesImpl:2.12.2'
- implementation('org.mustangproject:library:2.8.0') { // 2.10.0 did not
work, cf. OFBIZ-12920
(https://github.com/apache/ofbiz-framework/pull/712#issuecomment-1968960963)
+ implementation('org.mustangproject:library:2.26.0') { // 2.10.0 did not
work, cf. OFBIZ-12920
(https://github.com/apache/ofbiz-framework/pull/712#issuecomment-1968960963)
exclude group: 'pull-parser', module: 'pull-parser'
exclude group: 'xpp3', module: 'xpp3'
}
diff --git
a/framework/entity/src/main/java/org/apache/ofbiz/entity/serialize/XmlSerializer.java
b/framework/entity/src/main/java/org/apache/ofbiz/entity/serialize/XmlSerializer.java
index ce954005a7..e7e9eadd04 100644
---
a/framework/entity/src/main/java/org/apache/ofbiz/entity/serialize/XmlSerializer.java
+++
b/framework/entity/src/main/java/org/apache/ofbiz/entity/serialize/XmlSerializer.java
@@ -44,7 +44,7 @@ import java.util.TreeSet;
import java.util.Vector;
import java.util.WeakHashMap;
-import javax.xml.bind.DatatypeConverter;
+import jakarta.xml.bind.DatatypeConverter;
import javax.xml.parsers.ParserConfigurationException;
import org.apache.ofbiz.base.util.Debug;
diff --git
a/framework/security/src/main/java/org/apache/ofbiz/security/SecuredUpload.java
b/framework/security/src/main/java/org/apache/ofbiz/security/SecuredUpload.java
index ae8d0f0700..9a9f8d6817 100644
---
a/framework/security/src/main/java/org/apache/ofbiz/security/SecuredUpload.java
+++
b/framework/security/src/main/java/org/apache/ofbiz/security/SecuredUpload.java
@@ -93,6 +93,8 @@ import org.apache.ofbiz.base.util.UtilValidate;
import org.apache.ofbiz.base.util.UtilXml;
import org.apache.ofbiz.entity.Delegator;
import org.apache.ofbiz.entity.util.EntityUtilProperties;
+import org.apache.pdfbox.Loader;
+import org.apache.pdfbox.io.RandomAccessReadBufferedFile;
import org.apache.pdfbox.pdmodel.PDDocument;
import org.apache.pdfbox.pdmodel.PDDocumentNameDictionary;
import org.apache.pdfbox.pdmodel.PDEmbeddedFilesNameTreeNode;
@@ -1019,7 +1021,7 @@ public class SecuredUpload {
}
// OK no JS code, pass to check 2: detect if the document has any
embedded files
PDEmbeddedFilesNameTreeNode efTree = null;
- try (PDDocument pdDocument = PDDocument.load(file)) {
+ try (PDDocument pdDocument = Loader.loadPDF(new
RandomAccessReadBufferedFile(fileName))) {
PDDocumentNameDictionary names = new
PDDocumentNameDictionary(pdDocument.getDocumentCatalog());
efTree = names.getEmbeddedFiles();
}