From GitBox <>
Subject [GitHub] [jmeter] sseide opened a new pull request #641: update xercesImpl to 2.12.1 (from 2.12.0)
Date Tue, 26 Jan 2021 04:26:52 GMT

sseide opened a new pull request #641:

   ## Description
   ## Description
   
   within the current xercesImpl version 2.12.0 a vulnerabilities was found. It is fixed with
the update to 2.12.1.
   * CVE-2020-14338 (Improper Input Validation)
   ## Motivation and Context
   ## Motivation and Context
   
   Fix potential security problems
   ## How Has This Been Tested?
   ## How Has This Been Tested?
   
   
   run gradlew check, first run failed with one library (xstream) having changed as expected,
rerun with "-PupdateExpectedJars" switch and "-PchecksumUpdate".
   The following executions of gradlew check and gradlew test succeeded now.
   The update of the checksum was needed because the signer of the xercesImpl release has
changed and a new gpg key was used to sign the maven release? (see
   ## Screenshots (if appropriate):
   ## Types of changes
   ## Types of changes
   - Bug fix (non-breaking change which fixes an issue)
   ## Checklist:
   ## Checklist:
   
   - [x] My code follows the [code style][style-guide] of this project.
   - [x] I have updated the documentation accordingly.

