This is an automated email from the ASF dual-hosted git repository.

mridulpathak pushed a commit to branch release24.09
in repository https://gitbox.apache.org/repos/asf/ofbiz-framework.git


The following commit(s) were added to refs/heads/release24.09 by this push:
     new adc29886fa Bump org.mustangproject:library from 2.8.0 to 2.26.0 (#1803)
adc29886fa is described below

commit adc29886fa08d790665789ed923f27fa79b1026b
Author: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
AuthorDate: Sat Aug 29 15:59:26 2026 +0530

    Bump org.mustangproject:library from 2.8.0 to 2.26.0 (#1803)
    
    Bumps
    [org.mustangproject:library](https://github.com/ZUGFeRD/mustangproject)
    from 2.8.0 to 2.26.0.
    <details>
    <summary>Release notes</summary>
    <p><em>Sourced from <a
    
href="https://github.com/ZUGFeRD/mustangproject/releases";>org.mustangproject:library's
    releases</a>.</em></p>
    <blockquote>
    <h2>2.26.0</h2>
    <h2>New Features</h2>
    <ul>
    <li><a
    
href="https://redirect.github.com/ZUGFeRD/mustangproject/issues/1233";>#1233</a>
    Add Seller tax representative (BG-11) to CII profiles, excluding
    Minimum</li>
    <li>Import and Export TaxCurrencyCode (BT-6) and corresponding
    TaxTotalAmount (BT-111)</li>
    <li><a
    
href="https://redirect.github.com/ZUGFeRD/mustangproject/issues/1243";>#1243</a>
    Support TypeCode and ValueMeasure for ApplicableProductCharacteristic on
    EXTENDED profile.</li>
    </ul>
    <h2>Fixes</h2>
    <ul>
    <li>Upgrade CEN EN16931 Schematron from v1.3.15 to v1.3.16</li>
    <li><a
    
href="https://redirect.github.com/ZUGFeRD/mustangproject/issues/1225";>#1225</a>:
    fix fluent API for subclasses of TradeTax (Charge, Allowance,
    LogisticsServiceCharge)</li>
    <li>Modify valid version array in PDFValidator, add &quot;3p0&quot;</li>
    <li><a
    
href="https://redirect.github.com/ZUGFeRD/mustangproject/issues/1228";>#1228</a>
    Allow import of invoices with a LineTotalAmount having more than 2
    decimals. <a
    
href="https://redirect.github.com/ZUGFeRD/mustangproject/issues/1231";>#1231</a></li>
    <li><a
    
href="https://redirect.github.com/ZUGFeRD/mustangproject/issues/1229";>#1229</a>
    ZF_250 XSDs contain ten dangling schemaLocation references</li>
    <li><a
    
href="https://redirect.github.com/ZUGFeRD/mustangproject/issues/1219";>#1219</a>
    <a
    
href="https://redirect.github.com/ZUGFeRD/mustangproject/issues/1223";>#1223</a>
    <a
    
href="https://redirect.github.com/ZUGFeRD/mustangproject/issues/1220";>#1220</a>
    Prevent NPE in Item.enrichProductFromVATBreakdown for VAT category
    &quot;O&quot;.</li>
    <li>Upgrade com.fasterxml.jackson.core to 2.22.2 from 2.22.1</li>
    </ul>
    <h2>2.25.0</h2>
    <h2>Highlights</h2>
    <p>Support for ZUGFeRD 2.5.2 (=Factur-X 1.09.2, <a
    
href="https://redirect.github.com/ZUGFeRD/mustangproject/issues/1216";>#1216</a>)
    as well as support LogisticsServiceCharges (Zuschläge für Versand &amp;
    Verpackung, <a
    
href="https://redirect.github.com/ZUGFeRD/mustangproject/issues/228";>#228</a>)
    and fixing VeraPDF Vulnerabilities CVE-2026-54078 and CVE-2026-54079 (<a
    
href="https://redirect.github.com/ZUGFeRD/mustangproject/issues/1213";>#1213</a>)</p>
    <h2>Fixes</h2>
    <ul>
    <li><a
    
href="https://redirect.github.com/ZUGFeRD/mustangproject/issues/1207";>#1207</a>
    itemTotalNetAmount is null Exception when validating invoices</li>
    <li><a
    
href="https://redirect.github.com/ZUGFeRD/mustangproject/issues/925";>#925</a>
    Emit line-level CalculationPercent (BT-138) and BasisAmount (BT-137) for
    the EN16931 and XRechnung profiles, using the caller-supplied
    Allowance/Charge basis amount.</li>
    <li><a
    
href="https://redirect.github.com/ZUGFeRD/mustangproject/issues/1171";>#1171</a>
    Removed deprecated methods Item::getAllowances() Item::getCharges() and
    their last usage in ZUGFeRD2PullProvider.</li>
    <li><a
    
href="https://redirect.github.com/ZUGFeRD/mustangproject/issues/1174";>#1174</a>
    Fix UBL AllowanceCharge import, add missing percent/basisAmount aliases,
    dropped per-unit-price allowances</li>
    <li><a
    
href="https://redirect.github.com/ZUGFeRD/mustangproject/issues/1163";>#1163</a>
    Make doRecalculateItemPricesFromLineTotals() use more than the fixed
    scale of 4.</li>
    <li><a
    
href="https://redirect.github.com/ZUGFeRD/mustangproject/issues/1162";>#1162</a>
    Skip the elements &quot;Information&quot; and
    &quot;PayeeSpecifiedCreditorFinancialInstitution&quot; for basic
    profiles.</li>
    <li><a
    
href="https://redirect.github.com/ZUGFeRD/mustangproject/issues/1134";>#1134</a>
    Fix: Trade party universal communication id not imported when scheme is
    not &quot;email address&quot; (EM) but &quot;electronic address&quot;
    (0225).</li>
    <li><a
    
href="https://redirect.github.com/ZUGFeRD/mustangproject/issues/1150";>#1150</a>
    Remove [D].[M].[Y] after Rechnungsdatum in HTML visualization</li>
    <li><a
    
href="https://redirect.github.com/ZUGFeRD/mustangproject/issues/996";>#996</a>
    Omit ExemptionReason written to line item level for profile EN16931,
    some validators raise a warning or even an error</li>
    <li><a
    
href="https://redirect.github.com/ZUGFeRD/mustangproject/issues/1097";>#1097</a>
    Invoice importer: LegalOrganization id not imported (wrong node name
    'GlobalID' instead of 'ID' used)</li>
    <li><a
    
href="https://redirect.github.com/ZUGFeRD/mustangproject/issues/1151";>#1151</a>
    'BR-FXEXT-IC-08rev' in ZF 2.5 requires VAT exemption reason text and
    code for allowances and charges</li>
    <li><a
    
href="https://redirect.github.com/ZUGFeRD/mustangproject/issues/1145";>#1145</a>
    Document-level allowance with VAT category O emits RateApplicablePercent
    (violates BR-O-06)</li>
    <li>add disableArithmeticCheck() / --no-arithmetic-check option to skip
    the arithmetic recalculation pass during validation</li>
    <li><a
    
href="https://redirect.github.com/ZUGFeRD/mustangproject/issues/1167";>#1167</a>
    Upgrade com.fasterxml.jackson.core to 2.22.1 from 2.17.3</li>
    <li><a
    
href="https://redirect.github.com/ZUGFeRD/mustangproject/issues/1186";>#1186</a>
    Read Item LineTotalAmount from
    SpecifiedTradeSettlementLineMonetarySummation</li>
    <li><a
    
href="https://redirect.github.com/ZUGFeRD/mustangproject/issues/976";>#976</a>
    / <a
    
href="https://redirect.github.com/ZUGFeRD/mustangproject/issues/797";>#797</a>
    InvoiceImport: read ContractReferencedDocument/IssuerAssignedID into
    Invoice.contractReferencedDocument</li>
    <li><a
    
href="https://redirect.github.com/ZUGFeRD/mustangproject/issues/987";>#987</a>
    Show only the matching BIC per IBAN in invoice visualization</li>
    <li><a
    
href="https://redirect.github.com/ZUGFeRD/mustangproject/issues/982";>#982</a>
    Support TypeCodes 130 and 916 for AdditionalReferencedDocuments</li>
    <li><a
    
href="https://redirect.github.com/ZUGFeRD/mustangproject/issues/1202";>#1202</a>
    Support IndividualTradeProductInstance with BatchID and
    SupplierAssignedSerialID for EXTENDED Profile</li>
    <li><a
    
href="https://redirect.github.com/ZUGFeRD/mustangproject/issues/1205";>#1205</a>
    Refactoring of Invoice's DocumentReferences.</li>
    <li><a
    
href="https://redirect.github.com/ZUGFeRD/mustangproject/issues/1208";>#1208</a>
    Prevent NPE when generating XML invoice without issue date.</li>
    <li><a
    
href="https://redirect.github.com/ZUGFeRD/mustangproject/issues/1211";>#1211</a>
    Change to UBL 2.4 and add commandline option for profile and
    customization ID.</li>
    <li><a
    
href="https://redirect.github.com/ZUGFeRD/mustangproject/issues/1212";>#1212</a>
    Remove deprecated method
    IExportableTransaction::getTradeSettlementPayment.</li>
    <li><a
    
href="https://redirect.github.com/ZUGFeRD/mustangproject/issues/1215";>#1215</a>
    Removed duplicate code in ZUGFeRD2PullProvider, which lead to a
    duplicate DirectDebitMandateID.</li>
    <li><a
    
href="https://redirect.github.com/ZUGFeRD/mustangproject/issues/956";>#956</a>
    Import all SpecifiedTradePaymentTerms blocks, not just the last
    one.</li>
    </ul>
    <!-- raw HTML omitted -->
    </blockquote>
    <p>... (truncated)</p>
    </details>
    <details>
    <summary>Changelog</summary>
    <p><em>Sourced from <a
    
href="https://github.com/ZUGFeRD/mustangproject/blob/master/History.md";>org.mustangproject:library's
    changelog</a>.</em></p>
    <blockquote>
    <h1>2.26.0</h1>
    <p>2026-08-25</p>
    <ul>
    <li>Upgrade CEN EN16931 Schematron from v1.3.15 to v1.3.16</li>
    <li><a
    
href="https://redirect.github.com/ZUGFeRD/mustangproject/issues/1233";>#1233</a>
    Add Seller tax representative (BG-11) to CII profiles, excluding
    Minimum</li>
    <li>Import and Export TaxCurrencyCode (BT-6) and corresponding
    TaxTotalAmount (BT-111)</li>
    <li><a
    
href="https://redirect.github.com/ZUGFeRD/mustangproject/issues/1225";>#1225</a>:
    fix fluent API for subclasses of TradeTax (Charge, Allowance,
    LogisticsServiceCharge)</li>
    <li>Modify valid version array in PDFValidator, add &quot;3p0&quot;</li>
    <li><a
    
href="https://redirect.github.com/ZUGFeRD/mustangproject/issues/1228";>#1228</a>
    Allow import of invoices with a LineTotalAmount having more than 2
    decimals. <a
    
href="https://redirect.github.com/ZUGFeRD/mustangproject/issues/1231";>#1231</a></li>
    <li><a
    
href="https://redirect.github.com/ZUGFeRD/mustangproject/issues/1229";>#1229</a>
    ZF_250 XSDs contain ten dangling schemaLocation references</li>
    <li><a
    
href="https://redirect.github.com/ZUGFeRD/mustangproject/issues/1219";>#1219</a>
    <a
    
href="https://redirect.github.com/ZUGFeRD/mustangproject/issues/1223";>#1223</a>
    <a
    
href="https://redirect.github.com/ZUGFeRD/mustangproject/issues/1220";>#1220</a>
    Prevent NPE in Item.enrichProductFromVATBreakdown for VAT category
    &quot;O&quot;.</li>
    <li><a
    
href="https://redirect.github.com/ZUGFeRD/mustangproject/issues/1243";>#1243</a>
    Support TypeCode and ValueMeasure for ApplicableProductCharacteristic on
    EXTENDED profile.</li>
    <li>Upgrade com.fasterxml.jackson.core to 2.22.2 from 2.22.1</li>
    </ul>
    <h1>2.25.0</h1>
    <p>2026-08-04</p>
    <ul>
    <li><a
    
href="https://redirect.github.com/ZUGFeRD/mustangproject/issues/1216";>#1216</a>
    ZUGFeRD 2.5.2 and Factur-X 1.09.2</li>
    <li><a
    
href="https://redirect.github.com/ZUGFeRD/mustangproject/issues/1213";>#1213</a>
    VeraPDF Vulnerabilities CVE-2026-54078 and CVE-2026-54079</li>
    <li><a
    
href="https://redirect.github.com/ZUGFeRD/mustangproject/issues/1207";>#1207</a>
    itemTotalNetAmount is null Exception when validating invoices</li>
    <li><a
    
href="https://redirect.github.com/ZUGFeRD/mustangproject/issues/925";>#925</a>
    Emit line-level CalculationPercent (BT-138) and BasisAmount (BT-137) for
    the EN16931 and XRechnung profiles, using the caller-supplied
    Allowance/Charge basis amount.</li>
    <li><a
    
href="https://redirect.github.com/ZUGFeRD/mustangproject/issues/1171";>#1171</a>
    Removed deprecated methods Item::getAllowances() Item::getCharges() and
    their last usage in ZUGFeRD2PullProvider.</li>
    <li><a
    
href="https://redirect.github.com/ZUGFeRD/mustangproject/issues/228";>#228</a>
    Support LogisticsServiceCharges (Zuschläge für Versand &amp;
    Verpackung)</li>
    <li><a
    
href="https://redirect.github.com/ZUGFeRD/mustangproject/issues/1174";>#1174</a>
    Fix UBL AllowanceCharge import, add missing percent/basisAmount aliases,
    dropped per-unit-price allowances</li>
    <li><a
    
href="https://redirect.github.com/ZUGFeRD/mustangproject/issues/1163";>#1163</a>
    Make doRecalculateItemPricesFromLineTotals() use more than the fixed
    scale of 4.</li>
    <li><a
    
href="https://redirect.github.com/ZUGFeRD/mustangproject/issues/1162";>#1162</a>
    Skip the elements &quot;Information&quot; and
    &quot;PayeeSpecifiedCreditorFinancialInstitution&quot; for basic
    profiles.</li>
    <li><a
    
href="https://redirect.github.com/ZUGFeRD/mustangproject/issues/1134";>#1134</a>
    Fix: Trade party universal communication id not imported when scheme is
    not &quot;email address&quot; (EM) but &quot;electronic address&quot;
    (0225).</li>
    <li><a
    
href="https://redirect.github.com/ZUGFeRD/mustangproject/issues/1150";>#1150</a>
    Remove [D].[M].[Y] after Rechnungsdatum in HTML visualization</li>
    <li><a
    
href="https://redirect.github.com/ZUGFeRD/mustangproject/issues/996";>#996</a>
    Omit ExemptionReason written to line item level for profile EN16931,
    some validators raise a warning or even an error</li>
    <li><a
    
href="https://redirect.github.com/ZUGFeRD/mustangproject/issues/1097";>#1097</a>
    Invoice importer: LegalOrganization id not imported (wrong node name
    'GlobalID' instead of 'ID' used)</li>
    <li><a
    
href="https://redirect.github.com/ZUGFeRD/mustangproject/issues/1151";>#1151</a>
    'BR-FXEXT-IC-08rev' in ZF 2.5 requires VAT exemption reason text and
    code for allowances and charges</li>
    <li><a
    
href="https://redirect.github.com/ZUGFeRD/mustangproject/issues/1145";>#1145</a>
    Document-level allowance with VAT category O emits RateApplicablePercent
    (violates BR-O-06)</li>
    <li>add disableArithmeticCheck() / --no-arithmetic-check option to skip
    the arithmetic recalculation pass during validation</li>
    <li><a
    
href="https://redirect.github.com/ZUGFeRD/mustangproject/issues/1167";>#1167</a>
    Upgrade com.fasterxml.jackson.core to 2.22.1 from 2.17.3</li>
    <li><a
    
href="https://redirect.github.com/ZUGFeRD/mustangproject/issues/1186";>#1186</a>
    Read Item LineTotalAmount from
    SpecifiedTradeSettlementLineMonetarySummation</li>
    <li><a
    
href="https://redirect.github.com/ZUGFeRD/mustangproject/issues/976";>#976</a>
    / <a
    
href="https://redirect.github.com/ZUGFeRD/mustangproject/issues/797";>#797</a>
    InvoiceImport: read ContractReferencedDocument/IssuerAssignedID into
    Invoice.contractReferencedDocument</li>
    <li><a
    
href="https://redirect.github.com/ZUGFeRD/mustangproject/issues/987";>#987</a>
    Show only the matching BIC per IBAN in invoice visualization</li>
    <li><a
    
href="https://redirect.github.com/ZUGFeRD/mustangproject/issues/982";>#982</a>
    Support TypeCodes 130 and 916 for AdditionalReferencedDocuments</li>
    <li><a
    
href="https://redirect.github.com/ZUGFeRD/mustangproject/issues/1202";>#1202</a>
    Support IndividualTradeProductInstance with BatchID and
    SupplierAssignedSerialID for EXTENDED Profile</li>
    <li><a
    
href="https://redirect.github.com/ZUGFeRD/mustangproject/issues/1205";>#1205</a>
    Refactoring of Invoice's DocumentReferences.</li>
    <li><a
    
href="https://redirect.github.com/ZUGFeRD/mustangproject/issues/1208";>#1208</a>
    Prevent NPE when generating XML invoice without issue date.</li>
    <li><a
    
href="https://redirect.github.com/ZUGFeRD/mustangproject/issues/1211";>#1211</a>
    Change to UBL 2.4 and add commandline option for profile and
    customization ID.</li>
    <li><a
    
href="https://redirect.github.com/ZUGFeRD/mustangproject/issues/1212";>#1212</a>
    Remove deprecated method
    IExportableTransaction::getTradeSettlementPayment.</li>
    <li><a
    
href="https://redirect.github.com/ZUGFeRD/mustangproject/issues/1215";>#1215</a>
    Removed duplicate code in ZUGFeRD2PullProvider, which lead to a
    duplicate DirectDebitMandateID.</li>
    <li><a
    
href="https://redirect.github.com/ZUGFeRD/mustangproject/issues/956";>#956</a>
    Import all SpecifiedTradePaymentTerms blocks, not just the last
    one.</li>
    </ul>
    <!-- raw HTML omitted -->
    </blockquote>
    <p>... (truncated)</p>
    </details>
    <details>
    <summary>Commits</summary>
    <ul>
    <li><a
    
href="https://github.com/ZUGFeRD/mustangproject/commit/6bf5ab9551e2bf5510c012b8b48708e32a8bded1";><code>6bf5ab9</code></a>
    updated javadoc</li>
    <li><a
    
href="https://github.com/ZUGFeRD/mustangproject/commit/292a8ce2f891f4be799da669614c85023bd1d58f";><code>292a8ce</code></a>
    updated history</li>
    <li><a
    
href="https://github.com/ZUGFeRD/mustangproject/commit/659050bcf13236ab7d73cfdfd3973bf8241dbca1";><code>659050b</code></a>
    Upgrade com.fasterxml.jackson.core to 2.22.2 from 2.22.1.</li>
    <li><a
    
href="https://github.com/ZUGFeRD/mustangproject/commit/1a84b38baa51dcace54d99317058f0166203a2b3";><code>1a84b38</code></a>
    Fix wrong positioning of ApplicableProductCharacteristic.</li>
    <li><a
    
href="https://github.com/ZUGFeRD/mustangproject/commit/096db40a9806b0b5202028509dff3563efe7fc8c";><code>096db40</code></a>
    Remove debug System.out statement.</li>
    <li><a
    
href="https://github.com/ZUGFeRD/mustangproject/commit/2e3e07e3aedce7851f04e5172671718de877dbea";><code>2e3e07e</code></a>
    Support TypeCode / ValueMeasure for ApplicableProductCharacteristic on
    EXTEND...</li>
    <li><a
    
href="https://github.com/ZUGFeRD/mustangproject/commit/ee907d693656993643493f820d5cb65f723772df";><code>ee907d6</code></a>
    Do not import an embedded BG-24 attachment twice</li>
    <li><a
    
href="https://github.com/ZUGFeRD/mustangproject/commit/5576403074721b5fdfc9baa4182f70d490895b23";><code>5576403</code></a>
    Use Checktyle also for the test classes, fix checkstyle failures.</li>
    <li><a
    
href="https://github.com/ZUGFeRD/mustangproject/commit/212789adfca5ba518b93a823d6198b2475f94c8c";><code>212789a</code></a>
    Set ErrorHandler to SchemaFactory to get validation errors on incorrect
    xsd´s.</li>
    <li><a
    
href="https://github.com/ZUGFeRD/mustangproject/commit/7e263a7b403f26cc27b2fa64ed8141633097f2ff";><code>7e263a7</code></a>
    upated history</li>
    <li>Additional commits viewable in <a
    
href="https://github.com/ZUGFeRD/mustangproject/compare/core-2.8.0...core-2.26.0";>compare
    view</a></li>
    </ul>
    </details>
    <br />
    
    
    [![Dependabot compatibility
    
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=org.mustangproject:library&package-manager=gradle&previous-version=2.8.0&new-version=2.26.0)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)
    
    Dependabot will resolve any conflicts with this PR as long as you don't
    alter it yourself. You can also trigger a rebase manually by commenting
    `@dependabot rebase`.
    
    [//]: # (dependabot-automerge-start)
    [//]: # (dependabot-automerge-end)
    
    ---
    
    <details>
    <summary>Dependabot commands and options</summary>
    <br />
    
    You can trigger Dependabot actions by commenting on this PR:
    - `@dependabot rebase` will rebase this PR
    - `@dependabot recreate` will recreate this PR, overwriting any edits
    that have been made to it
    - `@dependabot show <dependency name> ignore conditions` will show all
    of the ignore conditions of the specified dependency
    - `@dependabot ignore this major version` will close this PR and stop
    Dependabot creating any more for this major version (unless you reopen
    the PR or upgrade to it yourself)
    - `@dependabot ignore this minor version` will close this PR and stop
    Dependabot creating any more for this minor version (unless you reopen
    the PR or upgrade to it yourself)
    - `@dependabot ignore this dependency` will close this PR and stop
    Dependabot creating any more for this dependency (unless you reopen the
    PR or upgrade to it yourself)
    
    
    </details>
    
    ---------
    
    Signed-off-by: dependabot[bot] <[email protected]>
    Co-authored-by: dependabot[bot] 
<49699333+dependabot[bot]@users.noreply.github.com>
    Co-authored-by: Suraj Rajan <[email protected]>
    Co-authored-by: Mridul Pathak <[email protected]>
---
 dependencies.gradle                                           | 11 ++++++-----
 .../java/org/apache/ofbiz/entity/serialize/XmlSerializer.java |  2 +-
 .../main/java/org/apache/ofbiz/security/SecuredUpload.java    |  4 +++-
 3 files changed, 10 insertions(+), 7 deletions(-)

diff --git a/dependencies.gradle b/dependencies.gradle
index 76d4447002..7f9aeb9736 100644
--- a/dependencies.gradle
+++ b/dependencies.gradle
@@ -49,14 +49,15 @@ dependencies {
     implementation 'org.apache.logging.log4j:log4j-api:2.26.1' // the API of 
log4j 2
     implementation 'org.apache.logging.log4j:log4j-core:2.26.1' // Somehow 
needed by Buildbot to compile OFBizDynamicThresholdFilter.java
     implementation 'org.apache.poi:poi:4.1.2' // poi-ooxml-schemas-5.0.0.pom'. 
Received status code 401 from server
-    implementation 'org.apache.pdfbox:pdfbox:2.0.37' // 3.0.1 does not compile
+    implementation 'org.apache.pdfbox:pdfbox:3.0.8'
+    implementation 'org.apache.pdfbox:pdfbox-io:3.0.8'
     implementation 'org.apache.shiro:shiro-core:1.13.0'
     implementation 'org.apache.shiro:shiro-crypto-cipher:2.2.1'
     implementation 'org.apache.sshd:sshd-core:2.19.0'
     implementation 'org.apache.sshd:sshd-sftp:2.19.0'
-    implementation 'org.apache.tika:tika-core:2.9.4'
-    implementation 'org.apache.tika:tika-parsers:2.9.4'
-    implementation 'org.apache.tika:tika-parser-pdf-module:2.9.4'
+    implementation 'org.apache.tika:tika-core:3.3.2'
+    implementation 'org.apache.tika:tika-parsers:3.3.2'
+    implementation 'org.apache.tika:tika-parser-pdf-module:3.3.2'
     implementation 'org.apache.cxf:cxf-rt-frontend-jaxrs:3.6.12' // 4.0.3 does 
not compile
     implementation 'org.apache.tomcat:tomcat-catalina-ha:9.0.121' // Remember 
to change the version number (9 now) in javadoc block if needed.
     implementation 'org.apache.tomcat:tomcat-jasper:9.0.121'
@@ -80,7 +81,7 @@ dependencies {
     implementation 'org.jdom:jdom:1.1.3' // don't upgrade above 1.1.3, makes a 
lot of not obvious and useless complications, see last commits of OFBIZ-12092 
for more
     implementation 'com.google.re2j:re2j:1.8'
     implementation 'xerces:xercesImpl:2.12.2'
-    implementation('org.mustangproject:library:2.8.0') { // 2.10.0 did not 
work, cf. OFBIZ-12920 
(https://github.com/apache/ofbiz-framework/pull/712#issuecomment-1968960963)
+    implementation('org.mustangproject:library:2.26.0') { // 2.10.0 did not 
work, cf. OFBIZ-12920 
(https://github.com/apache/ofbiz-framework/pull/712#issuecomment-1968960963)
       exclude group: 'pull-parser', module: 'pull-parser'
       exclude group: 'xpp3', module: 'xpp3'
     }
diff --git 
a/framework/entity/src/main/java/org/apache/ofbiz/entity/serialize/XmlSerializer.java
 
b/framework/entity/src/main/java/org/apache/ofbiz/entity/serialize/XmlSerializer.java
index ce954005a7..e7e9eadd04 100644
--- 
a/framework/entity/src/main/java/org/apache/ofbiz/entity/serialize/XmlSerializer.java
+++ 
b/framework/entity/src/main/java/org/apache/ofbiz/entity/serialize/XmlSerializer.java
@@ -44,7 +44,7 @@ import java.util.TreeSet;
 import java.util.Vector;
 import java.util.WeakHashMap;
 
-import javax.xml.bind.DatatypeConverter;
+import jakarta.xml.bind.DatatypeConverter;
 import javax.xml.parsers.ParserConfigurationException;
 
 import org.apache.ofbiz.base.util.Debug;
diff --git 
a/framework/security/src/main/java/org/apache/ofbiz/security/SecuredUpload.java 
b/framework/security/src/main/java/org/apache/ofbiz/security/SecuredUpload.java
index ae8d0f0700..9a9f8d6817 100644
--- 
a/framework/security/src/main/java/org/apache/ofbiz/security/SecuredUpload.java
+++ 
b/framework/security/src/main/java/org/apache/ofbiz/security/SecuredUpload.java
@@ -93,6 +93,8 @@ import org.apache.ofbiz.base.util.UtilValidate;
 import org.apache.ofbiz.base.util.UtilXml;
 import org.apache.ofbiz.entity.Delegator;
 import org.apache.ofbiz.entity.util.EntityUtilProperties;
+import org.apache.pdfbox.Loader;
+import org.apache.pdfbox.io.RandomAccessReadBufferedFile;
 import org.apache.pdfbox.pdmodel.PDDocument;
 import org.apache.pdfbox.pdmodel.PDDocumentNameDictionary;
 import org.apache.pdfbox.pdmodel.PDEmbeddedFilesNameTreeNode;
@@ -1019,7 +1021,7 @@ public class SecuredUpload {
             }
             // OK no JS code, pass to check 2: detect if the document has any 
embedded files
             PDEmbeddedFilesNameTreeNode efTree = null;
-            try (PDDocument pdDocument = PDDocument.load(file)) {
+            try (PDDocument pdDocument = Loader.loadPDF(new 
RandomAccessReadBufferedFile(fileName))) {
                 PDDocumentNameDictionary names = new 
PDDocumentNameDictionary(pdDocument.getDocumentCatalog());
                 efTree = names.getEmbeddedFiles();
             }

Reply via email to