ICEfaces
  1. ICEfaces
  2. ICE-10355

update commons-fileupload library to v1.3.1 for security fix for ice:inputFile

    Details

    • Type: Bug Bug
    • Status: Closed
    • Priority: Major Major
    • Resolution: Fixed
    • Affects Version/s: EE-1.8.2.GA_P07
    • Fix Version/s: EE-1.8.2.GA_P08
    • Component/s: ICE-Components
    • Labels:
      None
    • Environment:
      jsf 1.2 ICEfaces 1.8 file upload

      Description

      Security fix on commons-fileupload-1.2.1 which is bundled with 1.8.2_P03 to P07 has fix in commons-fileupload-1.3.1
      Will test with P07, then back to P03
      pache.org/proper/commons-fileupload/changes-report.html

        Issue Links

          Activity

          Hide
          Judy Guglielmin added a comment -

          rev 43837

          Show
          Judy Guglielmin added a comment - rev 43837
          Hide
          Ken Fyten added a comment -

          My own testing shows that file upload is not working on latest icefaces trunk.

          Show
          Ken Fyten added a comment - My own testing shows that file upload is not working on latest icefaces trunk.
          Hide
          Ken Fyten added a comment -

          My failures were due to inadvertently testing on Tomcat 8. It works fine for me on Tomcat 7.

          1) The files with '0' size are not uploaded, and a message is rendered on page: "The request was rejected because it's size is unknown" - is this correct behavior?

          Yes, a file with size 0 is not a valid file to upload.

          2) None of the uploaded files could be found on the server.

          They seem to be located under the webapps/component-showcase/upload directory for me.

          Marking this Resolved.

          Show
          Ken Fyten added a comment - My failures were due to inadvertently testing on Tomcat 8. It works fine for me on Tomcat 7. 1) The files with '0' size are not uploaded, and a message is rendered on page: "The request was rejected because it's size is unknown" - is this correct behavior? Yes, a file with size 0 is not a valid file to upload. 2) None of the uploaded files could be found on the server. They seem to be located under the webapps/component-showcase/upload directory for me. Marking this Resolved.
          Hide
          Carmen Cristurean added a comment - - edited

          ICEfaces 1.8.2.GA_P08 Jenkins Build# 1:
          Verified file upload in component-showcase[facelets-enh/facelets] on WAS 8.5.5.4, WAS 6.1.0.0.

          Show
          Carmen Cristurean added a comment - - edited ICEfaces 1.8.2.GA_P08 Jenkins Build# 1: Verified file upload in component-showcase [facelets-enh/facelets] on WAS 8.5.5.4, WAS 6.1.0.0.
          Hide
          Liana Munroe added a comment -

          ICEfaces 1.8.2.GA_P08 Jenkins Build# 1:
          Verified file upload in component-showcase[facelets-enh/facelets] WebLogic 12.1.3, WebLogic 8.1, JBoss 5.1, glassfish 3.1.2.2, tomcat 7.

          Show
          Liana Munroe added a comment - ICEfaces 1.8.2.GA_P08 Jenkins Build# 1: Verified file upload in component-showcase [facelets-enh/facelets] WebLogic 12.1.3, WebLogic 8.1, JBoss 5.1, glassfish 3.1.2.2, tomcat 7.

            People

            • Assignee:
              Judy Guglielmin
              Reporter:
              Judy Guglielmin
            • Votes:
              0 Vote for this issue
              Watchers:
              4 Start watching this issue

              Dates

              • Created:
                Updated:
                Resolved: