mirror of https://github.com/OpenIdentityPlatform/OpenDJ.git

Valery Kharseko
2 days ago 58666fd764de42df1615625ea5623dcc1a1a6e15
Bump FreeMarker to 2.3.35 and fix the loadObjectClassesToMaps javadoc (#1176)

Two code scanning alerts on `master`.

### Alert 1297: FreeMarker 2.3.34 → 2.3.35 (CVE-2026-84939)

FreeMarker before 2.3.35 resolves a malformed locale identifier into a
path outside the template root. Trivy reports it on
`opt/opendj/lib/org.freemarker.freemarker.jar` of the image built from
`master` (`trivy-build-alpine`).

In OpenDJ it is not reachable: FreeMarker only renders OpenDJ's own
templates, in `DocGenerationHelper` (opendj-cli) and the doc maven
plugin, and nothing takes a locale from a client. The jar ships in
`lib/` all the same, so the alert stays open until the version moves.
commons made the same bump in OpenIdentityPlatform/commons#311.

All three `Configuration` instances are built with
`Configuration.DEFAULT_INCOMPATIBLE_IMPROVEMENTS`, a fixed constant, so
the template behaviour does not follow the library version.

### Alert 1281: `CompressedSchema.loadObjectClassesToMaps` javadoc

The javadoc listed a `sync` parameter the method does not have (left
over from #920) and documented `mappings` twice, with the encode and
decode maps the wrong way round.

### Not in this PR

- jackson 2.18.9 → 2.18.11 (alerts 1302, 1305–1308) and netty-handler
4.2.15 → 4.2.17+ (alert 1284) come from the commons parent
(`jackson.version`, `netty-bom`), so they belong in a commons change and
a `commons.version` bump.
- The `trivy-image-*` alerts are on the published 5.1.2 image; `master`
already carries the fixed versions (bc-fips 2.1.3, jackson 2.18.9,
postgresql 42.7.12, mssql-jdbc 13.4.0, a fresh base image). They close
with the next release.

### Testing

`mvn -pl opendj-cli,opendj-doc-maven-plugin -am package -DskipTests`
builds with 2.3.35. The documentation generation itself runs in CI.
2 files modified
9 ■■■■■ changed files
opendj-server-legacy/src/main/java/org/opends/server/api/CompressedSchema.java 7 ●●●●● patch | view | raw | blame | history
pom.xml 2 ●●●●● patch | view | raw | blame | history
opendj-server-legacy/src/main/java/org/opends/server/api/CompressedSchema.java
@@ -949,11 +949,8 @@
   * @param objectClassNames
   *          The user provided set of object class names.
   * @param mappings
   *          .ocEncodeMap maps id to entry
   * @param mappings
   *          .ocDecodeMap maps entry to id
   * @param sync
   *          indicates if update of maps should be synchronized
   *          the mappings to load into: {@code ocEncodeMap} maps the object class set to the id,
   *          {@code ocDecodeMap} maps the id to the object class set.
   * @return The object class set.
   */
  private Map<ObjectClass, String> loadObjectClassesToMaps(int id, final Collection<String> objectClassNames,
pom.xml
@@ -36,7 +36,7 @@
        <project.build.sourceEncoding>UTF-8</project.build.sourceEncoding>
        <localized.jars.classifier>i18n</localized.jars.classifier>
        <commons.version>3.2.0</commons.version>
        <freemarker.version>2.3.34</freemarker.version>
        <freemarker.version>2.3.35</freemarker.version>
        <metrics-core.version>4.2.30</metrics-core.version>
        <bc.fips.version>2.1.3</bc.fips.version>
        <bctls.fips.version>2.1.24</bctls.fips.version>