[
https://issues.apache.org/jira/browse/OFBIZ-11709?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17110167#comment-17110167 ]
ASF subversion and git services commented on OFBIZ-11709:
---------------------------------------------------------
Commit babd23282ee61f1b840899a3785e89da5f202131 in ofbiz-framework's branch refs/heads/release17.12 from Jacques Le Roux
[
https://gitbox.apache.org/repos/asf?p=ofbiz-framework.git;h=babd232 ]
Improved: Prevent FreeMarker Template Injection (SSTI)
(OFBIZ-11709)
Some people may want to use another TemplateClassResolver than SAFER_RESOLVER
This creates a new templateClassResolver security property and uses it in
FreeMarkerWorker::makeConfiguration by default
Conflicts all handled by hand (no merge possible)
--
This message was sent by Atlassian Jira
(v8.3.4#803005)