[
https://issues.apache.org/jira/browse/OFBIZ-11709?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17110168#comment-17110168 ]
ASF subversion and git services commented on OFBIZ-11709:
---------------------------------------------------------
Commit b97d6bf1e28c1ffc062af08fc7da2769fc3672d5 in ofbiz-framework's branch refs/heads/release18.12 from Jacques Le Roux
[
https://gitbox.apache.org/repos/asf?p=ofbiz-framework.git;h=b97d6bf ]
Improved: Prevent FreeMarker Template Injection (SSTI)
(OFBIZ-11709)
Some people may want to use another TemplateClassResolver than SAFER_RESOLVER
This creates a new templateClassResolver security property and uses it in
FreeMarkerWorker::makeConfiguration by default
Conflicts handled by hand
framework/security/config/security.properties
--
This message was sent by Atlassian Jira
(v8.3.4#803005)