<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Important security alert in Alfresco Archive</title>
    <link>https://connect.hyland.com/t5/alfresco-archive/important-security-alert/m-p/263700#M216830</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;Thank you to direct attention to this issue and for providing an instant fix!&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;For the XSLT issue, it is maybe possible to disable XSLT if this functionality is not required or while the patch is being prepared:&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;For 4.0d Community Edition place a file security-fixes-context.xml into /shared/classes/alfresco/extension containing:&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;lt;?xml version='1.0' encoding='UTF-8'?&amp;gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;lt;!DOCTYPE beans PUBLIC '-//SPRING//DTD BEAN//EN' '&lt;/SPAN&gt;&lt;A href="http://www.springframework.org/dtd/spring-beans.dtd" rel="nofollow noopener noreferrer"&gt;http://www.springframework.org/dtd/spring-beans.dtd&lt;/A&gt;&lt;SPAN&gt;'&amp;gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;lt;beans&amp;gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp; &amp;lt;!– override xslt beans to disable xslt processing –&amp;gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp; &amp;lt;!– &lt;/SPAN&gt;&lt;A href="https://forums.alfresco.com/en/viewtopic.php?f=2&amp;amp;t=44384" rel="nofollow noopener noreferrer"&gt;https://forums.alfresco.com/en/viewtopic.php?f=2&amp;amp;t=44384&lt;/A&gt;&lt;SPAN&gt; –&amp;gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp; &amp;lt;!– &lt;/SPAN&gt;&lt;A href="https://issues.alfresco.com/jira/browse/ALF-13726" rel="nofollow noopener noreferrer"&gt;https://issues.alfresco.com/jira/browse/ALF-13726&lt;/A&gt;&lt;SPAN&gt; –&amp;gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp; &amp;lt;bean id="xsltRenderingEngine" class="java.lang.String"/&amp;gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp; &amp;lt;bean id="xsltFunctions" class="java.lang.String"/&amp;gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp; &amp;lt;bean id="xsltProcessor" class="java.lang.String"/&amp;gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;lt;/beans&amp;gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Regards,&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp; lothar&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 27 Apr 2012 11:12:18 GMT</pubDate>
    <dc:creator>lotharmärkle</dc:creator>
    <dc:date>2012-04-27T11:12:18Z</dc:date>
    <item>
      <title>Important security alert</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/important-security-alert/m-p/263699#M216829</link>
      <description>Included in Alfresco 4.0.1 Enterprise is a fix for two critical security issues. The two issues are&lt;IMG id="smileyfrustrated" class="emoticon emoticon-smileyfrustrated" src="https://migration33.stage.lithium.com/i/smilies/16x16_smiley-frustrated.png" alt="Smiley Frustrated" title="Smiley Frustrated" /&gt;OLR REST API allows unauthenticated access to repository contents (ALF-13721) (Affects 4.0)Remote code execution possible via Web Script XSLT Processor (ALF-13726) (Affects all versions)If you are an</description>
      <pubDate>Thu, 26 Apr 2012 23:13:58 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/important-security-alert/m-p/263699#M216829</guid>
      <dc:creator>jpotts</dc:creator>
      <dc:date>2012-04-26T23:13:58Z</dc:date>
    </item>
    <item>
      <title>Re: Important security alert</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/important-security-alert/m-p/263700#M216830</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;Thank you to direct attention to this issue and for providing an instant fix!&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;For the XSLT issue, it is maybe possible to disable XSLT if this functionality is not required or while the patch is being prepared:&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;For 4.0d Community Edition place a file security-fixes-context.xml into /shared/classes/alfresco/extension containing:&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;lt;?xml version='1.0' encoding='UTF-8'?&amp;gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;lt;!DOCTYPE beans PUBLIC '-//SPRING//DTD BEAN//EN' '&lt;/SPAN&gt;&lt;A href="http://www.springframework.org/dtd/spring-beans.dtd" rel="nofollow noopener noreferrer"&gt;http://www.springframework.org/dtd/spring-beans.dtd&lt;/A&gt;&lt;SPAN&gt;'&amp;gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;lt;beans&amp;gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp; &amp;lt;!– override xslt beans to disable xslt processing –&amp;gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp; &amp;lt;!– &lt;/SPAN&gt;&lt;A href="https://forums.alfresco.com/en/viewtopic.php?f=2&amp;amp;t=44384" rel="nofollow noopener noreferrer"&gt;https://forums.alfresco.com/en/viewtopic.php?f=2&amp;amp;t=44384&lt;/A&gt;&lt;SPAN&gt; –&amp;gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp; &amp;lt;!– &lt;/SPAN&gt;&lt;A href="https://issues.alfresco.com/jira/browse/ALF-13726" rel="nofollow noopener noreferrer"&gt;https://issues.alfresco.com/jira/browse/ALF-13726&lt;/A&gt;&lt;SPAN&gt; –&amp;gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp; &amp;lt;bean id="xsltRenderingEngine" class="java.lang.String"/&amp;gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp; &amp;lt;bean id="xsltFunctions" class="java.lang.String"/&amp;gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp; &amp;lt;bean id="xsltProcessor" class="java.lang.String"/&amp;gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;lt;/beans&amp;gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Regards,&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp; lothar&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 27 Apr 2012 11:12:18 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/important-security-alert/m-p/263700#M216830</guid>
      <dc:creator>lotharmärkle</dc:creator>
      <dc:date>2012-04-27T11:12:18Z</dc:date>
    </item>
  </channel>
</rss>

