manifoldcf-commits mailing list archives

Site index · List index
Message view « Date » · « Thread »
Top « Date » · « Thread »
From kwri...@apache.org
Subject svn commit: r1618770 - in /manifoldcf/trunk: CHANGES.txt build.xml connectors/gts/pom.xml connectors/sharepoint/connector/src/main/java/org/apache/manifoldcf/crawler/connectors/sharepoint/SPSProxyHelper.java connectors/tika/pom.xml pom.xml
Date Tue, 19 Aug 2014 00:22:18 GMT
Author: kwright
Date: Tue Aug 19 00:22:18 2014
New Revision: 1618770

URL: http://svn.apache.org/r1618770
Log:
Fix for CONNECTORS-1012.

Modified:
    manifoldcf/trunk/CHANGES.txt
    manifoldcf/trunk/build.xml
    manifoldcf/trunk/connectors/gts/pom.xml
    manifoldcf/trunk/connectors/sharepoint/connector/src/main/java/org/apache/manifoldcf/crawler/connectors/sharepoint/SPSProxyHelper.java
    manifoldcf/trunk/connectors/tika/pom.xml
    manifoldcf/trunk/pom.xml

Modified: manifoldcf/trunk/CHANGES.txt
URL: http://svn.apache.org/viewvc/manifoldcf/trunk/CHANGES.txt?rev=1618770&r1=1618769&r2=1618770&view=diff
==============================================================================
--- manifoldcf/trunk/CHANGES.txt (original)
+++ manifoldcf/trunk/CHANGES.txt Tue Aug 19 00:22:18 2014
@@ -5,6 +5,9 @@ $Id$
 
 ======================= Release 1.7 =====================
 
+CONNECTORS-1012: Upgrade xmlbeans and POI to fix various CVE's.
+(Karl Wright)
+
 CONNECTORS-1011: Upgrade to httpclient 4.3.5.
 (Karl Wright)
 

Modified: manifoldcf/trunk/build.xml
URL: http://svn.apache.org/viewvc/manifoldcf/trunk/build.xml?rev=1618770&r1=1618769&r2=1618770&view=diff
==============================================================================
--- manifoldcf/trunk/build.xml (original)
+++ manifoldcf/trunk/build.xml Tue Aug 19 00:22:18 2014
@@ -1035,7 +1035,7 @@ Use Apache Forrest version forrest-0.9-d
         <mkdir dir="lib"/>
         <antcall target="download-via-maven"><param name="target" value="lib"/>
             <param name="project-path" value="org/apache/poi"/>
-            <param name="artifact-version" value="3.10-beta2"/>
+            <param name="artifact-version" value="3.10.1"/>
             <param name="artifact-name" value="poi"/>
             <param name="artifact-type" value="jar"/>
         </antcall>
@@ -1645,7 +1645,7 @@ Use Apache Forrest version forrest-0.9-d
         <antcall target="download-via-maven"><param name="target" value="lib"/>
             <param name="project-path" value="org/apache/poi"/>
             <param name="artifact-name" value="poi-scratchpad"/>
-            <param name="artifact-version" value="3.10-beta2"/>
+            <param name="artifact-version" value="3.10.1"/>
             <param name="artifact-type" value="jar"/>
         </antcall>
         <antcall target="download-via-maven"><param name="target" value="lib"/>
@@ -1669,7 +1669,7 @@ Use Apache Forrest version forrest-0.9-d
         <antcall target="download-via-maven"><param name="target" value="lib"/>
             <param name="project-path" value="org/apache/xmlbeans"/>
             <param name="artifact-name" value="xmlbeans"/>
-            <param name="artifact-version" value="2.3.0"/>
+            <param name="artifact-version" value="2.6.0"/>
             <param name="artifact-type" value="jar"/>
         </antcall>
         <antcall target="download-via-maven"><param name="target" value="lib"/>
@@ -1753,13 +1753,13 @@ Use Apache Forrest version forrest-0.9-d
         <antcall target="download-via-maven"><param name="target" value="lib"/>
             <param name="project-path" value="org/apache/poi"/>
             <param name="artifact-name" value="poi-ooxml"/>
-            <param name="artifact-version" value="3.10-beta2"/>
+            <param name="artifact-version" value="3.10.1"/>
             <param name="artifact-type" value="jar"/>
         </antcall>
         <antcall target="download-via-maven"><param name="target" value="lib"/>
             <param name="project-path" value="org/apache/poi"/>
             <param name="artifact-name" value="poi-ooxml-schemas"/>
-            <param name="artifact-version" value="3.10-beta2"/>
+            <param name="artifact-version" value="3.10.1"/>
             <param name="artifact-type" value="jar"/>
         </antcall>
         <antcall target="download-via-maven"><param name="target" value="lib"/>

Modified: manifoldcf/trunk/connectors/gts/pom.xml
URL: http://svn.apache.org/viewvc/manifoldcf/trunk/connectors/gts/pom.xml?rev=1618770&r1=1618769&r2=1618770&view=diff
==============================================================================
--- manifoldcf/trunk/connectors/gts/pom.xml (original)
+++ manifoldcf/trunk/connectors/gts/pom.xml Tue Aug 19 00:22:18 2014
@@ -199,7 +199,7 @@
     <dependency>
       <groupId>org.apache.poi</groupId>
       <artifactId>poi</artifactId>
-      <version>3.7</version>
+      <version>${poi.version}</version>
     </dependency>
     
     <!-- Testing dependencies -->

Modified: manifoldcf/trunk/connectors/sharepoint/connector/src/main/java/org/apache/manifoldcf/crawler/connectors/sharepoint/SPSProxyHelper.java
URL: http://svn.apache.org/viewvc/manifoldcf/trunk/connectors/sharepoint/connector/src/main/java/org/apache/manifoldcf/crawler/connectors/sharepoint/SPSProxyHelper.java?rev=1618770&r1=1618769&r2=1618770&view=diff
==============================================================================
--- manifoldcf/trunk/connectors/sharepoint/connector/src/main/java/org/apache/manifoldcf/crawler/connectors/sharepoint/SPSProxyHelper.java
(original)
+++ manifoldcf/trunk/connectors/sharepoint/connector/src/main/java/org/apache/manifoldcf/crawler/connectors/sharepoint/SPSProxyHelper.java
Tue Aug 19 00:22:18 2014
@@ -174,7 +174,16 @@ public class SPSProxyHelper {
             if ( roleName.length() == 0)
             {
               roleName = doc.getValue(node,"GroupName");
-              roleSids = getSidsForGroup(userCall, roleName, activeDirectoryAuthority);
+              if (roleName != null && roleName.length() > 0)
+              {
+                System.out.println("Saw group name '"+roleName+"'");
+                roleSids = getSidsForGroup(userCall, roleName, activeDirectoryAuthority);
+              }
+              else
+              {
+                Logging.connectors.warn("SharePoint: Unrecognized permission collection entry:
no role, no group: "+doc.getXML());
+                roleSids = new ArrayList<String>();
+              }
             }
             else
             {

Modified: manifoldcf/trunk/connectors/tika/pom.xml
URL: http://svn.apache.org/viewvc/manifoldcf/trunk/connectors/tika/pom.xml?rev=1618770&r1=1618769&r2=1618770&view=diff
==============================================================================
--- manifoldcf/trunk/connectors/tika/pom.xml (original)
+++ manifoldcf/trunk/connectors/tika/pom.xml Tue Aug 19 00:22:18 2014
@@ -221,6 +221,33 @@
 	  <artifactId>tika-parsers</artifactId>
 	  <version>1.5</version>
     </dependency>
+    <!-- Override tika dependencies, to make sure we fix various
+      CVE's -->
+    <dependency>
+	  <groupId>org.apache.xmlbeans</groupId>
+	  <artifactId>xmlbeans</artifactId>
+	  <version>${xmlbeans.version}</version>
+    </dependency>
+    <dependency>
+	  <groupId>org.apache.poi</groupId>
+	  <artifactId>poi</artifactId>
+	  <version>${poi.version}</version>
+    </dependency>
+    <dependency>
+	  <groupId>org.apache.poi</groupId>
+	  <artifactId>poi-ooxml</artifactId>
+	  <version>${poi.version}</version>
+    </dependency>
+    <dependency>
+	  <groupId>org.apache.poi</groupId>
+	  <artifactId>poi-ooxml-schemas</artifactId>
+	  <version>${poi.version}</version>
+    </dependency>
+    <dependency>
+	  <groupId>org.apache.poi</groupId>
+	  <artifactId>poi-scratchpad</artifactId>
+	  <version>${poi.version}</version>
+    </dependency>
     
     <!-- Testing dependencies -->
     

Modified: manifoldcf/trunk/pom.xml
URL: http://svn.apache.org/viewvc/manifoldcf/trunk/pom.xml?rev=1618770&r1=1618769&r2=1618770&view=diff
==============================================================================
--- manifoldcf/trunk/pom.xml (original)
+++ manifoldcf/trunk/pom.xml Tue Aug 19 00:22:18 2014
@@ -75,6 +75,8 @@
     <slf4j.version>1.7.7</slf4j.version>
     <jaxb.version>2.2.6</jaxb.version>
     <zookeeper.version>3.4.5</zookeeper.version>
+    <xmlbeans.version>2.6.0</xmlbeans.version>
+    <poi.version>3.10.1</poi.version>
   </properties>
 
   <modules>



Mime
View raw message