Skip to content

Commit c38eda0

Browse files
committed
Add / refine / complete details not addressed by sempf's content.
1 parent ba43950 commit c38eda0

File tree

1 file changed

+132
-115
lines changed

1 file changed

+132
-115
lines changed
Lines changed: 132 additions & 115 deletions
Original file line numberDiff line numberDiff line change
@@ -1,115 +1,132 @@
1-
Release notes for ESAPI 2.2.1.0
2-
Release date: 2020-TBD
3-
Project leaders:
4-
-Kevin W. Wall <[email protected]>
5-
-Matt Seil <[email protected]>
6-
7-
Previous release: ESAPI 2.2.0.0, 2019-June-24
8-
9-
10-
Executive Summary: Important Things to Note for this Release
11-
------------------------------------------------------------
12-
13-
TBD
14-
15-
=================================================================================================================
16-
17-
Basic ESAPI facts
18-
19-
ESAPI 2.2.0.0 release:
20-
194 Java source files
21-
4150 JUnit tests in 118 Java source files
22-
23-
ESAPI 2.2.1.0 release:
24-
TBD
25-
26-
GitHub Issues fixed in this release
27-
28-
Issue # GitHub Issue Title
29-
----------------------------------------------------------------------------------------------
30-
31-
143 Enchance encodeForOS to auto-detect the underling OS
32-
226 Javadoc Inaccuracy in getRandomInteger() and getRandomReal()
33-
245 KeyDerivationFunction::computeDerivedKey - possible security level mismatch
34-
256 White space clean up
35-
382 Build Fails on path with space
36-
494 Encoder's encodeForCSS doesn't handle RGB Triplets
37-
503 Bug on on referrer header when value contains `&section` like `www.asdf.com?a=1&section=2`
38-
509 HTMLValidationRule.getValid(String,String) does not follow documented specifications
39-
511 Add missing documentation to Validator.addRule() and Validator.getRule()
40-
512 Update Apache Commons Bean Utils to 1.9.4
41-
515 Adding tests for getCookies (also 516)
42-
519 Issue 494 CSSCodec RGB Triplets
43-
530 Log Bridge Tests
44-
536 Various fixes
45-
538 Addressing log4j 1.x CVE-2019-17571
46-
47-
-----------------------------------------------------------------------------
48-
49-
Changes requiring special attention
50-
51-
-----------------------------------------------------------------------------
52-
53-
TBD
54-
55-
-----------------------------------------------------------------------------
56-
57-
Other changes in this release, some of which not tracked via GitHub issues
58-
59-
-----------------------------------------------------------------------------
60-
61-
Documentation updates for locating Jar files
62-
Unneeded code removed from ExtensiveEncoder
63-
Inline reader added to ExtensiveEncoder
64-
Additional time for windows to always sleep more than given seconds in CryptoTokenTest
65-
Change required by tweak to CipherText.toString() method
66-
Removed call to deprecated CryptoHelper.computeDerivedKey() method
67-
New JUnit tests for org.owasp.esapi.crypto.KeyDerivationFunction class
68-
Use existing toString method rather than a StringBuilder
69-
Documentation and tests
70-
JavaLogger move
71-
Splitting user infor from Client Supplier
72-
73-
-----------------------------------------------------------------------------
74-
75-
Developer Activity Report (Changes between release 2.2.0.0 and 2.2.1.0, i.e., between 2019-06-25 and 2020-05-12)
76-
Generated manually (this time)
77-
78-
Developer Total commits Total Number
79-
of Files Changed
80-
=====================================================
81-
jeremiahjstacey 11 68
82-
kwwall 15 26
83-
wiitek 3 6
84-
xeno6696 8 9
85-
Michael-Ziluck 2 3
86-
=====================================================
87-
88-
-----------------------------------------------------------------------------
89-
90-
53 Closed PRs since 2.2.0.0 release
91-
===================================
92-
504 New scripts to suppress noise for 'mvn test'
93-
510 Resolve #509 - Properly throw exception when HTML fails
94-
513 Close issue #512 by updating to 1.9.4 of Commons Beans Util.\
95-
519 Issue 494 CSSCodec RGB Triplets
96-
520 OS Name DefaultExecutorTests #143
97-
540 Issue 382: Build Fails on path with space
98-
596 Closes Issue 245
99-
100-
-----------------------------------------------------------------------------
101-
102-
Notice:
103-
104-
Release notes written by Bill Sempf ([email protected]) please direct any communication to me.
105-
106-
Project co-leaders
107-
Kevin W. Wall (kwwall)
108-
Matt Seil (xeno6696)
109-
110-
Special shout-outs to:
111-
Jeremiah Stacey (jeremiahjstacey) -- All around ESAPI support and JUnit test case developer extraordinaire
112-
Dave Wichers (davewichers) - for Maven Central / Sonatype help
113-
114-
Thanks you all for your time and effort to ESAPI and making it a better project. And if I've missed any, my apologies; let me know and I will correct it.
115-
1+
Release notes for ESAPI 2.2.1.0
2+
Release date: 2020-July-??
3+
Project leaders:
4+
-Kevin W. Wall <[email protected]>
5+
-Matt Seil <[email protected]>
6+
7+
Previous release: ESAPI 2.2.0.0, 2019-June-24
8+
9+
10+
Executive Summary: Important Things to Note for this Release
11+
------------------------------------------------------------
12+
13+
This is a minor release. It's main purpose was to update dependencies to eliminate potential vulnerabilities arising from dependencies with known CVEs. See the section "Changes requiring special attention" below for additional details.
14+
15+
Also special props to Bill Sempf for stepping up and volunteering to prepare the initial cut of these release notes. Had he not done so, this release either would not have release notes or it would have been delayed another 6 months while I procrastinated further with various distractions. (Squirrel!)
16+
17+
=================================================================================================================
18+
19+
Basic ESAPI facts
20+
-----------------
21+
22+
ESAPI 2.2.0.0 release:
23+
194 Java source files
24+
4150 JUnit tests in 118 Java source files
25+
26+
ESAPI 2.2.1.0 release:
27+
211 Java source files
28+
4309 JUnit tests in 134 Java source files
29+
30+
GitHub Issues fixed in this release
31+
32+
Issue # GitHub Issue Title
33+
----------------------------------------------------------------------------------------------
34+
35+
143 Enchance encodeForOS to auto-detect the underling OS
36+
226 Javadoc Inaccuracy in getRandomInteger() and getRandomReal()
37+
245 KeyDerivationFunction::computeDerivedKey - possible security level mismatch
38+
256 White space clean up
39+
382 Build Fails on path with space
40+
494 Encoder's encodeForCSS doesn't handle RGB Triplets
41+
503 Bug on on referrer header when value contains `&section` like `www.asdf.com?a=1&section=2`
42+
509 HTMLValidationRule.getValid(String,String) does not follow documented specifications
43+
511 Add missing documentation to Validator.addRule() and Validator.getRule()
44+
512 Update Apache Commons Bean Utils to 1.9.4
45+
515 Adding tests for getCookies (also 516)
46+
519 Issue 494 CSSCodec RGB Triplets
47+
522 javadoc corrections for Encoder.canonicalize()
48+
530 Log Bridge Tests
49+
536 Various fixes
50+
538 Addressing log4j 1.x CVE-2019-17571
51+
52+
-----------------------------------------------------------------------------
53+
54+
Changes requiring special attention
55+
56+
-----------------------------------------------------------------------------
57+
The new default ESAPI logger is JUL (java.util.logging packages) and we have deprecated the use of Log4j 1.x as it is way past the end-of-life and we now support SLF4J. We did not want to make SLF4J the default logger (at least not yet) as we did not want to have the default ESAPI use require additional dependencies. However, SLF4J is likely to be the future choice, at least once we start on EsAPI 3.0. A special shout-out to Jeremiah Stacey for making this possible by re-factoring much of the ESAPI logger code. Note, the straw that broke the proverbial camel's back was the announcement of CVE-2019-17571 (rated Critical), for which there is no fix available and likely will never be.
58+
59+
Related to that CVE and how it affects ESAPI, be sure to read
60+
https://github.com/ESAPI/esapi-java-legacy/blob/develop/documentation/ESAPI-security-bulletin2.pdf
61+
which describes CVE-2019-17571, a deserialization vulnerability in Log4j 1.2.17. ESAPI is not affected by this (even if you chose to use Log4j 1 as you default ESAPI logger). This security bulletin describes why this CVE is not exploitable as used by ESAPI.
62+
63+
Notable dependency updates (excludes those only used with JUnit tests):
64+
antiSamy 1.5.8 -> 1.5.10
65+
batik-css 1.11 -> 1.13
66+
commons-beansutil 1.9.3 -> 1.9.4
67+
slf4j-api 1.7.26 -> 1.7.30
68+
69+
Finally, while ESAPI still supports JDK 7 (even though that too is way past end-of-life), the next ESAPI release will move to JDK 8 as the minimal baseline. (We already use Java 8 for development but still to Java 7 source and runtime compatiblity.)
70+
71+
-----------------------------------------------------------------------------
72+
73+
Other changes in this release, some of which not tracked via GitHub issues
74+
75+
-----------------------------------------------------------------------------
76+
77+
Documentation updates for locating Jar files
78+
Unneeded code removed from ExtensiveEncoder
79+
Inline reader added to ExtensiveEncoder
80+
Additional time for windows to always sleep more than given seconds in CryptoTokenTest
81+
Change required by tweak to CipherText.toString() method
82+
Removed call to deprecated CryptoHelper.computeDerivedKey() method
83+
New JUnit tests for org.owasp.esapi.crypto.KeyDerivationFunction class
84+
Use existing toString method rather than a StringBuilder
85+
Documentation and tests
86+
JavaLogger moved
87+
Splitting user info from Client Supplier
88+
89+
-----------------------------------------------------------------------------
90+
91+
Developer Activity Report (Changes between release 2.2.0.0 and 2.2.1.0, i.e., between 2019-06-25 and 2020-05-12)
92+
Generated manually (this time)
93+
94+
Developer Total Total Number
95+
(GitHub ID) commits of Files Changed
96+
=====================================================
97+
jeremiahjstacey 11 68
98+
kwwall 15 26
99+
wiitek 3 6
100+
xeno6696 8 9
101+
Michael-Ziluck 2 3
102+
sempf 1 1
103+
=====================================================
104+
105+
-----------------------------------------------------------------------------
106+
107+
53 Closed PRs since 2.2.0.0 release
108+
===================================
109+
504 New scripts to suppress noise for 'mvn test'
110+
510 Resolve #509 - Properly throw exception when HTML fails
111+
513 Close issue #512 by updating to 1.9.4 of Commons Beans Util.\
112+
519 Issue 494 CSSCodec RGB Triplets
113+
520 OS Name DefaultExecutorTests #143
114+
540 Issue 382: Build Fails on path with space
115+
596 Closes Issue 245
116+
117+
-----------------------------------------------------------------------------
118+
119+
Notice:
120+
121+
Release notes written by Bill Sempf ([email protected]), but please direct any communication to the project leaders.
122+
123+
Project co-leaders
124+
Kevin W. Wall (kwwall)
125+
Matt Seil (xeno6696)
126+
127+
Special shout-outs to:
128+
Jeremiah Stacey (jeremiahjstacey) -- All around ESAPI support and JUnit test case developer extraordinaire
129+
Dave Wichers (davewichers) - for Maven Central / Sonatype help
130+
Bill Sempf -- for these release notes. Awesome job, Bill. I owe you a brew.
131+
132+
Thanks you all for your time and effort to ESAPI and making it a better project. And if I've missed any, my apologies; let me know and I will correct it.

0 commit comments

Comments
 (0)