Severity: Medium
Vendor:
The Apache Software Foundation
Versions Affected:
Sling CMS 0.14.0 and previous releases
Description:
Scripts in Sling CMS do not property escape the Sling Selector from URLs
when generating navigational elements for the administrative consoles and
are vulnerable to
[
https://issues.apache.org/jira/browse/SLING-8953?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
]
Dan Klco closed SLING-8953.
---
> CMS - Closing Search Issues
> ---
>
> Key: SLING-8953
>
[
https://issues.apache.org/jira/browse/SLING-8871?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
]
Dan Klco closed SLING-8871.
---
> CMS - Upload Click Handler Registered Multiple Times
>
>
[
https://issues.apache.org/jira/browse/SLING-8947?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
]
Dan Klco closed SLING-8947.
---
> CMS - Grid View Missing Fields
> --
>
> Key: SLING-8947
>
[
https://issues.apache.org/jira/browse/SLING-8872?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
]
Dan Klco closed SLING-8872.
---
> CMS - Fails to Extract JPEG Metadata
>
>
> Key:
[
https://issues.apache.org/jira/browse/SLING-8930?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
]
Dan Klco closed SLING-8930.
---
> CMS - i18n Not Reloading
>
>
> Key: SLING-8930
> URL:
[
https://issues.apache.org/jira/browse/SLING-8956?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
]
Dan Klco closed SLING-8956.
---
> Archetype Token Replacement Issues
> --
>
> Key: SLING-8956
>
[
https://issues.apache.org/jira/browse/SLING-9156?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
]
Dan Klco closed SLING-9156.
---
> CMS - Add Thumbnail to Search
> -
>
> Key: SLING-9156
>
[
https://issues.apache.org/jira/browse/SLING-9152?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
]
Dan Klco closed SLING-9152.
---
> CMS Reference - Use Commons Messaging Mail
> --
>
>
[
https://issues.apache.org/jira/browse/SLING-9226?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
]
Dan Klco closed SLING-9226.
---
> CMS - Move Fails with Same Name Resources
> -
>
> Key:
[
https://issues.apache.org/jira/browse/SLING-9001?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
]
Dan Klco closed SLING-9001.
---
> CMS - Cannot Create Page without Template Policy
>
>
>
[
https://issues.apache.org/jira/browse/SLING-8957?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
]
Dan Klco closed SLING-8957.
---
> Tika Fallback Provider Fails on Large Files
> ---
>
>
[
https://issues.apache.org/jira/browse/SLING-9225?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
]
Dan Klco closed SLING-9225.
---
> CMS - Add JCR Cleanup Schedulers
>
>
> Key: SLING-9225
>
[
https://issues.apache.org/jira/browse/SLING-8952?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
]
Dan Klco closed SLING-8952.
---
> CMS - Use Bulma Tags Instead of Buttons for Labelfield
>
[
https://issues.apache.org/jira/browse/SLING-8958?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
]
Dan Klco closed SLING-8958.
---
> Return Default Thumbnail on Error
> -
>
> Key: SLING-8958
>
[
https://issues.apache.org/jira/browse/SLING-8917?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
]
Dan Klco closed SLING-8917.
---
> CMS - Add Support for LDAP
> --
>
> Key: SLING-8917
>
[
https://issues.apache.org/jira/browse/SLING-9000?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
]
Dan Klco closed SLING-9000.
---
> CMS - Reload Fails When Editing Component
> -
>
> Key:
[
https://issues.apache.org/jira/browse/SLING-9242?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
]
Oliver Lietz resolved SLING-9242.
-
Resolution: Done
> Update Pax Exam to 4.13.3
> -
>
>
Oliver Lietz created SLING-9242:
---
Summary: Update Pax Exam to 4.13.3
Key: SLING-9242
URL: https://issues.apache.org/jira/browse/SLING-9242
Project: Sling
Issue Type: Task
Components:
[
https://issues.apache.org/jira/browse/SLING-9247?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
]
Yegor Kozlov updated SLING-9247:
External issue URL: (was:
Oliver Lietz created SLING-9243:
---
Summary: Update to Sling Bundle Parent 38
Key: SLING-9243
URL: https://issues.apache.org/jira/browse/SLING-9243
Project: Sling
Issue Type: Task
Yegor Kozlov created SLING-9247:
---
Summary: Improve Performance Of Testing Ignored GET Parameters
Key: SLING-9247
URL: https://issues.apache.org/jira/browse/SLING-9247
Project: Sling
Issue
[
https://issues.apache.org/jira/browse/SLING-9247?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
]
Yegor Kozlov updated SLING-9247:
External issue URL:
https://github.com/apache/sling-org-apache-sling-dynamic-include/pull/15
>
Oliver Lietz created SLING-9244:
---
Summary: Update Pax Exam to 4.13.3
Key: SLING-9244
URL: https://issues.apache.org/jira/browse/SLING-9244
Project: Sling
Issue Type: Task
Components:
[
https://issues.apache.org/jira/browse/SLING-9244?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
]
Oliver Lietz resolved SLING-9244.
-
Resolution: Done
* Pax Exam updated
* Testing PaxExam updated
* Proper OSGi dependencies added
[
https://issues.apache.org/jira/browse/SLING-9248?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
]
A. J. David Bosschaert updated SLING-9248:
--
Description:
Feature model variables are not resolved for array elements.
A. J. David Bosschaert created SLING-9248:
-
Summary: Feature model variables are not resolved for array
elements
Key: SLING-9248
URL: https://issues.apache.org/jira/browse/SLING-9248
Project:
[
https://issues.apache.org/jira/browse/SLING-9243?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
]
Oliver Lietz resolved SLING-9243.
-
Resolution: Done
> Update to Sling Bundle Parent 38
>
>
>
[
https://issues.apache.org/jira/browse/SLING-9246?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
]
Oliver Lietz resolved SLING-9246.
-
Resolution: Done
* Pax Exam updated
* Proper OSGi dependencies added
> Update Pax Exam to
[
https://issues.apache.org/jira/browse/SLING-9245?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
]
Oliver Lietz resolved SLING-9245.
-
Resolution: Done
> Update to Sling Bundle Parent 38
>
>
>
Oliver Lietz created SLING-9246:
---
Summary: Update Pax Exam to 4.13.3
Key: SLING-9246
URL: https://issues.apache.org/jira/browse/SLING-9246
Project: Sling
Issue Type: Task
Components:
Oliver Lietz created SLING-9245:
---
Summary: Update to Sling Bundle Parent 38
Key: SLING-9245
URL: https://issues.apache.org/jira/browse/SLING-9245
Project: Sling
Issue Type: Task
YegorKozlov opened a new pull request #15: use Set instead of a List to test
ignoreUrlParams
URL: https://github.com/apache/sling-org-apache-sling-dynamic-include/pull/15
In our setup we have a list of ignored GET parameters
(_include-filter.config.ignoreUrlParams_) which grew with time
[
https://issues.apache.org/jira/browse/SLING-9219?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17065497#comment-17065497
]
Konrad Windszus commented on SLING-9219:
Thanks for the heads up, the compilation issue should be
Any more PMC votes?
On Fri, Mar 20, 2020 at 12:41 PM Daniel Klco wrote:
> +1
>
> On Fri, Mar 20, 2020 at 12:37 PM Robert Munteanu
> wrote:
>
>> On Fri, 2020-03-20 at 12:12 -0400, Daniel Klco wrote:
>> > Please vote to approve this release:
>>
>> +1
>> Robert
>>
>
sonarcloud[bot] commented on issue #15: use Set instead of a List to test
ignoreUrlParams
URL:
https://github.com/apache/sling-org-apache-sling-dynamic-include/pull/15#issuecomment-603126478
Kudos, SonarCloud Quality Gate passed!
rombert commented on issue #15: use Set instead of a List to test
ignoreUrlParams
URL:
https://github.com/apache/sling-org-apache-sling-dynamic-include/pull/15#issuecomment-603126532
Thanks for the PR @YegorKozlov . Can you please amend the commit message to
reference the Jira issue you
[
https://issues.apache.org/jira/browse/SLING-9249?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
]
Robert Munteanu updated SLING-9249:
---
Attachment: log.txt
> Exception thrown when running the Sling Starter - UseRuntimeException:
[
https://issues.apache.org/jira/browse/SLING-9249?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
]
Robert Munteanu updated SLING-9249:
---
Description:
To reproduce: run {{mvn clean verify}} on the current sling starter -
[
https://issues.apache.org/jira/browse/SLING-9169?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
]
Robert Munteanu closed SLING-9169.
--
> Installer core should shade embedded classes
>
>
>
[
https://issues.apache.org/jira/browse/SLING-9168?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
]
Robert Munteanu closed SLING-9168.
--
> Installer core should not imbed javax / johnzon
>
[
https://issues.apache.org/jira/browse/SLING-9219?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
]
Carsten Ziegeler reopened SLING-9219:
-
JCR Installer does not compile anymore :
[
https://issues.apache.org/jira/browse/SLING-9184?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
]
Robert Munteanu closed SLING-9184.
--
> BundleInstallUpgradeDowngradeTest fails
> ---
>
>
[
https://issues.apache.org/jira/browse/SLING-9167?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
]
Robert Munteanu closed SLING-9167.
--
> Installer core embeds too many config admin classes
>
[
https://issues.apache.org/jira/browse/SLING-9166?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
]
Robert Munteanu closed SLING-9166.
--
> Installer core must not depend on org.osgi.service.event
>
[
https://issues.apache.org/jira/browse/SLING-9172?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
]
Robert Munteanu closed SLING-9172.
--
> Allow Sling Installer to install and handle multiple versions of bundles
> instead of updating
Hi,
The vote has passed with the following result:
+1 (binding): Dan Klco, Robert Munteanu, Carsten Ziegeler, Konrad
Windszus
+1 (non-binding): none
I will copy this release to the Sling dist directory and
promote the artifacts to the central Maven repository.
Regards,
Robert Munteanu
+1
On Tue, 24 Mar 2020 at 12:37, Daniel Klco wrote:
> Any more PMC votes?
>
> On Fri, Mar 20, 2020 at 12:41 PM Daniel Klco wrote:
>
> > +1
> >
> > On Fri, Mar 20, 2020 at 12:37 PM Robert Munteanu
> > wrote:
> >
> >> On Fri, 2020-03-20 at 12:12 -0400, Daniel Klco wrote:
> >> > Please vote to
Robert Munteanu created SLING-9249:
--
Summary: Exception thrown when running the Sling Starter -
Key: SLING-9249
URL: https://issues.apache.org/jira/browse/SLING-9249
Project: Sling
Issue
[
https://issues.apache.org/jira/browse/SLING-9249?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
]
Robert Munteanu updated SLING-9249:
---
Summary: Exception thrown when running the Sling Starter -
UseRuntimeException: The
[
https://issues.apache.org/jira/browse/SLING-9249?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17065493#comment-17065493
]
Robert Munteanu commented on SLING-9249:
[~radu] - not sure if this has other side effects, but
[
https://issues.apache.org/jira/browse/SLING-9219?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17065491#comment-17065491
]
Carsten Ziegeler edited comment on SLING-9219 at 3/24/20, 10:28 AM:
[
https://issues.apache.org/jira/browse/SLING-9252?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
]
Radu Cotescu resolved SLING-9252.
-
Resolution: Fixed
Fixed in [commit
[
https://issues.apache.org/jira/browse/SLING-9171?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
]
Bertrand Delacretaz reassigned SLING-9171:
--
Assignee: Bertrand Delacretaz
> Support for settings properties on paths
Hi,
The vote has passed with the following result:
+1 (binding): Robert Munteanu, Dan Klco, Andrei Dulvac
+1 (non-binding): none
I will copy this release to the Sling dist directory and promote the
artifacts to the central Maven repository.
Regards,
Dan Klco
On Tue, Mar 24, 2020 at 7:41 AM
[
https://issues.apache.org/jira/browse/SLING-9219?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
]
Carsten Ziegeler resolved SLING-9219.
-
Resolution: Fixed
Thanks [~kwin] for the quick fix.
> Invalid Comments in JSON
[
https://issues.apache.org/jira/browse/SLING-9250?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
]
Radu Cotescu resolved SLING-9250.
-
Resolution: Fixed
Fixed in [commit
Radu Cotescu created SLING-9252:
---
Summary: Optimise request dispatching for inheriting resource types
Key: SLING-9252
URL: https://issues.apache.org/jira/browse/SLING-9252
Project: Sling
Issue
Nitin Gupta created SLING-9253:
--
Summary: Feature archive gives EOFException while reading
Key: SLING-9253
URL: https://issues.apache.org/jira/browse/SLING-9253
Project: Sling
Issue Type: Bug
[
https://issues.apache.org/jira/browse/SLING-9253?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
]
Carsten Ziegeler updated SLING-9253:
Component/s: Feature Model
> Feature archive gives EOFException while reading
>
[
https://issues.apache.org/jira/browse/SLING-9253?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
]
Carsten Ziegeler updated SLING-9253:
Affects Version/s: slingfeature-maven-plugin 1.1.20
> Feature archive gives EOFException
[
https://issues.apache.org/jira/browse/SLING-9253?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
]
Carsten Ziegeler updated SLING-9253:
Fix Version/s: slingfeature-maven-plugin 1.1.22
> Feature archive gives EOFException while
[
https://issues.apache.org/jira/browse/SLING-9251?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
]
Oliver Lietz updated SLING-9251:
Summary: Update Pax Exam to 4.13.3 (was: Update Pax Exam to 4.13.2)
> Update Pax Exam to 4.13.3
>
Oliver Lietz created SLING-9251:
---
Summary: Update Pax Exam to 4.13.2
Key: SLING-9251
URL: https://issues.apache.org/jira/browse/SLING-9251
Project: Sling
Issue Type: Task
Components:
[
https://issues.apache.org/jira/browse/SLING-9251?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
]
Oliver Lietz resolved SLING-9251.
-
Resolution: Done
* Pax Exam updated
* Testing PaxExam updated
> Update Pax Exam to 4.13.3
>
[
https://issues.apache.org/jira/browse/SLING-9250?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
]
Radu Cotescu updated SLING-9250:
Description: The fix for SLING-9216 slipped a bug where a capability's
selectors are used for
Radu Cotescu created SLING-9250:
---
Summary: Selectors are used as extensions when servlets are
registered for a capability
Key: SLING-9250
URL: https://issues.apache.org/jira/browse/SLING-9250
Project:
[
https://issues.apache.org/jira/browse/SLING-9253?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
]
Carsten Ziegeler reassigned SLING-9253:
---
Assignee: Carsten Ziegeler
> Feature archive gives EOFException while reading
>
[
https://issues.apache.org/jira/browse/SLING-9171?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17065932#comment-17065932
]
Bertrand Delacretaz commented on SLING-9171:
Naming is hard...thank you [~jsedding], Nitin
[
https://issues.apache.org/jira/browse/SLING-9253?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
]
Carsten Ziegeler resolved SLING-9253.
-
Resolution: Fixed
Fixed in
[
https://issues.apache.org/jira/browse/SLING-9171?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17066011#comment-17066011
]
Nitin Gupta edited comment on SLING-9171 at 3/24/20, 5:31 PM:
--
Thanks
[
https://issues.apache.org/jira/browse/SLING-9171?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17066011#comment-17066011
]
Nitin Gupta commented on SLING-9171:
Thanks [~bdelacretaz], agree that moving the parsing logic to
[
https://issues.apache.org/jira/browse/SLING-9171?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17066082#comment-17066082
]
Nitin Gupta commented on SLING-9171:
Incorporated the corresponding jcr-repoinit changes also atÂ
73 matches
Mail list logo