Re: using cocoon 2.1 in the long-term, security concerns

Leszek Gawron <[email protected]> Fri, 30 Jul 2021 10:33:25 +0200
Newsgroups gmane.text.xml.cocoon.user
Message-ID <CAM3qyxLyebipaha_6Q5YEGg8f4ydagzZq5VExKa7UyvAmx7Hhw@mail.gmail.com>
--00000000000059032105c853134c
Content-Type: text/plain; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

On Mon, Jul 19, 2021 at 2:27 PM C=C3=A9dric Damioli <[email protected]> w=
rote:

> Hi,
>
> Not only Tomcat, but each and every dependency your particular project
> uses.
> As of today, Cocoon 2.1 works well in a Java 11+/Tomcat 9+ environment,
> with all dependencies upgraded.
>
> Cocoon 2.1.13 itself contained a fix for a security-related issue, but in
> the past years, there wasn't many security issues targeting Cocoon core.
>
>
cocoon 2.2 does NOT work with spring 4+ - the fixes are trivial though
(some deprecated API usages have to be corrected)
Jetty 9 needs to have web fragments configuration disabled or it doesn't
start cocoon webapp at all

I've made some forked changes for my organization and ... lost the sources.
Fixing it again should be no problem if someone here would go for a
release.

Java 11 is no problem - the only thing I remember is some simple
commons-beanutils usage querying Java version - the forced maven dependency
fixed the issue.

--00000000000059032105c853134c
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr"><div dir=3D"ltr">On Mon, Jul 19, 2021 at 2:27 PM C=C3=A9dr=
ic Damioli &lt;<a href=3D"mailto:[email protected]">[email protected]</=
a>&gt; wrote:<br></div><div class=3D"gmail_quote"><blockquote class=3D"gmai=
l_quote" style=3D"margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,20=
4,204);padding-left:1ex">
 =20
   =20
 =20
  <div>
    Hi,<br>
    <br>
    Not only Tomcat, but each and every dependency your particular
    project uses.<br>
    As of today, Cocoon 2.1 works well in a Java 11+/Tomcat 9+
    environment, with all dependencies upgraded.<br>
    <br>
    Cocoon 2.1.13 itself contained a fix for a security-related issue,
    but in the past years, there wasn&#39;t many security issues targeting
    Cocoon core.<br><br></div></blockquote><div><br></div><div>cocoon 2.2 d=
oes NOT work with spring 4+ - the fixes are trivial though (some deprecated=
 API usages have to be corrected)</div><div>Jetty 9 needs to have web fragm=
ents configuration disabled or it doesn&#39;t start cocoon webapp at all=C2=
=A0</div><div><br></div><div>I&#39;ve made some forked changes for my organ=
ization and ... lost the sources. Fixing it again should be no problem if s=
omeone here would go for a release.=C2=A0</div><div><br></div><div>Java 11 =
is no problem - the only thing I remember is some simple commons-beanutils =
usage querying Java version - the forced maven dependency fixed the issue.<=
/div><div><br></div><div>=C2=A0</div></div></div>

--00000000000059032105c853134c--