Skip to content

Bump FreeMarker to 2.3.35 and fix the loadObjectClassesToMaps javadoc - #1176

Merged
vharseko merged 1 commit into
OpenIdentityPlatform:masterfrom
vharseko:issue/code-scanning-freemarker-javadoc
Oct 6, 2026
Merged

vharseko merged 1 commit into
OpenIdentityPlatform:masterfrom
vharseko:issue/code-scanning-freemarker-javadoc

Conversation

@vharseko

@vharseko vharseko commented Oct 6, 2026

Copy link
Copy Markdown
Member

Two code scanning alerts on master.

Alert 1297: FreeMarker 2.3.34 → 2.3.35 (CVE-2026-84939)

FreeMarker before 2.3.35 resolves a malformed locale identifier into a path outside the template root. Trivy reports it on opt/opendj/lib/org.freemarker.freemarker.jar of the image built from master (trivy-build-alpine).

In OpenDJ it is not reachable: FreeMarker only renders OpenDJ's own templates, in DocGenerationHelper (opendj-cli) and the doc maven plugin, and nothing takes a locale from a client. The jar ships in lib/ all the same, so the alert stays open until the version moves. commons made the same bump in OpenIdentityPlatform/commons#311.

All three Configuration instances are built with Configuration.DEFAULT_INCOMPATIBLE_IMPROVEMENTS, a fixed constant, so the template behaviour does not follow the library version.

Alert 1281: CompressedSchema.loadObjectClassesToMaps javadoc

The javadoc listed a sync parameter the method does not have (left over from #920) and documented mappings twice, with the encode and decode maps the wrong way round.

Not in this PR

  • jackson 2.18.9 → 2.18.11 (alerts 1302, 1305–1308) and netty-handler 4.2.15 → 4.2.17+ (alert 1284) come from the commons parent (jackson.version, netty-bom), so they belong in a commons change and a commons.version bump.
  • The trivy-image-* alerts are on the published 5.1.2 image; master already carries the fixed versions (bc-fips 2.1.3, jackson 2.18.9, postgresql 42.7.12, mssql-jdbc 13.4.0, a fresh base image). They close with the next release.

Testing

mvn -pl opendj-cli,opendj-doc-maven-plugin -am package -DskipTests builds with 2.3.35. The documentation generation itself runs in CI.

CVE-2026-84939 (code scanning alert 1297): FreeMarker before 2.3.35
resolves a malformed locale identifier into a path outside the template
root. OpenDJ only renders its own templates, for the generated
documentation, so it is not reachable, but the jar ships in lib/.

The javadoc of CompressedSchema.loadObjectClassesToMaps listed a "sync"
parameter the method does not have and documented "mappings" twice, with
the encode and decode maps the wrong way round (alert 1281).
@vharseko
vharseko requested a review from maximthomas October 6, 2026 08:08
@vharseko vharseko added dependencies Pull requests that update a dependency file security Security fixes / CodeQL code-scanning alerts java Changes to Java sources labels Oct 6, 2026

@maximthomas maximthomas left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@vharseko
vharseko merged commit 58666fd into OpenIdentityPlatform:master Oct 6, 2026
23 checks passed
@vharseko
vharseko deleted the issue/code-scanning-freemarker-javadoc branch October 6, 2026 11:34
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file java Changes to Java sources security Security fixes / CodeQL code-scanning alerts

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants