From bd90f8d4409ed9923fabbc7de8f6064963510469 Mon Sep 17 00:00:00 2001 From: Dannes Wessels Date: Mon, 10 Jul 2023 22:37:50 +0200 Subject: [PATCH] [security] update xalan version including explicit reference to serializer --- exist-core/pom.xml | 10 ++++++++-- exist-parent/pom.xml | 1 + 2 files changed, 9 insertions(+), 2 deletions(-) diff --git a/exist-core/pom.xml b/exist-core/pom.xml index 378cb1bf578..3eb7fa81542 100644 --- a/exist-core/pom.xml +++ b/exist-core/pom.xml @@ -364,7 +364,7 @@ xalan xalan - 2.7.3 + ${xalan.version} xml-apis @@ -373,6 +373,12 @@ + + xalan + serializer + ${xalan.version} + + net.sf.saxon Saxon-HE @@ -989,7 +995,7 @@ The BaseX Team. The original license statement is also included below.]]>org.apache.logging.log4j:log4j-jcl:jar:${log4j.version} org.apache.logging.log4j:log4j-slf4j2-impl:jar:${log4j.version} org.apache.logging.log4j:log4j-jul:jar:${log4j.version} - + xalan:serializer:jar:${xalan.version} org.eclipse.angus:angus-activation:jar:${eclipse.angus-activation.version} org.glassfish.jaxb:jaxb-runtime:jar:${jaxb.impl.version} org.fusesource.jansi:jansi:jar:2.4.0 diff --git a/exist-parent/pom.xml b/exist-parent/pom.xml index 9b1923908ff..77c3e99d987 100644 --- a/exist-parent/pom.xml +++ b/exist-parent/pom.xml @@ -119,6 +119,7 @@ 1.8.1.3 1.8.1.3-jakarta5 9.9.1-8 + 2.7.3 4.6.4 2.9.1 4.13.2