FISH-5811 Upgrade Apache Santuario to 2.2.3 #5505
Merged
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Description
CVE-2021-40690 identified a security issue with Santuario versions prior to 2.2.3 and 2.1.7. This PR updates our patched repo to 2.2.3 which also can run on JDK14+
Important Info
Blockers
Requires PR in patched-src-metro-wsit to be merged: payara/patched-src-metro-wsit#11
Testing
New tests
None
Testing Performed
All unit tests. Tested server starts and admin console loads
Testing Environment
Windows 10, Maven 3.6.3, JDK 8 and JDK 17
Documentation
Community Documentation PR: payara/Payara-Community-Documentation#277
Notes for Reviewers
Webservices 2.4.3.payara-p6 hasn't been built and uploaded to nexus yet. This will be done when the blocking PR is approved.