Uploaded image for project: 'Marmotta (Retired)'
  1. Marmotta (Retired)
  2. MARMOTTA-263

Fix frame injection bug in javadocs generated with Java 6 (and Java 7 prior u25)

    XMLWordPrintableJSON

Details

    • Bug
    • Status: Resolved
    • Critical
    • Resolution: Fixed
    • None
    • None
    • Website

    Description

      The Apache Infra / Security team posted to all committers:

      Hi All,
      Oracle has announced [1], [2] a frame injection vulnerability in Javadoc generated by Java 5, Java 6 and Java 7 before update 22.
      [...]
      Please take the necessary steps to fix any currently published Javadoc and to ensure that any future Javadoc published by your project does not contain the vulnerability. The announcement by Oracle includes a link to a tool that can be used to fix Javadoc without regeneration.
      The infrastructure team is investigating options for preventing the publication of vulnerable Javadoc.
      The issue is public and may be discussed freely on your project's dev list.
      Thanks,
      Mark (ASF Infra)

      For the moment, due a bug with multiple reports (see http://jira.codehaus.org/browse/MSHARED-271 for further details), our site only is affected by one instance.

      The buildbot+maven environment still uses Java6, so all the workaround in the maven plugin (https://jira.codehaus.org/browse/MJAVADOC-370) wouldn't be enough...

      Attachments

        Issue Links

          Activity

            People

              wikier Sergio Fernández
              wikier Sergio Fernández
              Votes:
              0 Vote for this issue
              Watchers:
              3 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved:

                Time Tracking

                  Estimated:
                  Original Estimate - 2h
                  2h
                  Remaining:
                  Remaining Estimate - 2h
                  2h
                  Logged:
                  Time Spent - Not Specified
                  Not Specified