<workflowRun _class='org.jenkinsci.plugins.workflow.job.WorkflowRun'><action _class='hudson.model.CauseAction'><cause _class='hudson.triggers.TimerTrigger$TimerTriggerCause'><shortDescription>Lancé par une alarme périodique</shortDescription></cause></action><action _class='hudson.model.ParametersAction'><parameter _class='hudson.model.BooleanParameterValue'><name>SKIP_TEST</name><value>false</value></parameter><parameter _class='hudson.model.BooleanParameterValue'><name>SKIP_QUALITY</name><value>false</value></parameter></action><action _class='org.jenkinsci.plugins.workflow.libs.LibrariesAction'></action><action></action><action _class='org.jenkinsci.plugins.workflow.cps.EnvActionImpl'></action><action _class='hudson.plugins.git.util.BuildData'><buildsByBranchName><refsremotesoriginmaster _class='hudson.plugins.git.util.Build'><buildNumber>571</buildNumber><marked><SHA1>56f5661a313b8828cac18f92b68f2f116fbd2cc2</SHA1><branch><SHA1>56f5661a313b8828cac18f92b68f2f116fbd2cc2</SHA1><name>refs/remotes/origin/master</name></branch></marked><revision><SHA1>56f5661a313b8828cac18f92b68f2f116fbd2cc2</SHA1><branch><SHA1>56f5661a313b8828cac18f92b68f2f116fbd2cc2</SHA1><name>refs/remotes/origin/master</name></branch></revision></refsremotesoriginmaster></buildsByBranchName><lastBuiltRevision><SHA1>56f5661a313b8828cac18f92b68f2f116fbd2cc2</SHA1><branch><SHA1>56f5661a313b8828cac18f92b68f2f116fbd2cc2</SHA1><name>refs/remotes/origin/master</name></branch></lastBuiltRevision><remoteUrl>https://github.com/Silverpeas/Jenkins-Pipelines.git</remoteUrl><scmName></scmName></action><action></action><action></action><action></action><action></action><action _class='hudson.plugins.git.util.BuildData'><buildsByBranchName><refsremotesorigin6.2.x _class='hudson.plugins.git.util.Build'><buildNumber>180</buildNumber><marked><SHA1>45e0d31d27a05fd6c36b5f7bd604a0d05f7f378f</SHA1><branch><SHA1>45e0d31d27a05fd6c36b5f7bd604a0d05f7f378f</SHA1><name>refs/remotes/origin/6.2.x</name></branch></marked><revision><SHA1>45e0d31d27a05fd6c36b5f7bd604a0d05f7f378f</SHA1><branch><SHA1>45e0d31d27a05fd6c36b5f7bd604a0d05f7f378f</SHA1><name>refs/remotes/origin/6.2.x</name></branch></revision></refsremotesorigin6.2.x><refsremotesorigin6.3.x _class='hudson.plugins.git.util.Build'><buildNumber>302</buildNumber><marked><SHA1>6df43e66c82d74fdaf07c75d56db339cf3491364</SHA1><branch><SHA1>6df43e66c82d74fdaf07c75d56db339cf3491364</SHA1><name>refs/remotes/origin/6.3.x</name></branch></marked><revision><SHA1>6df43e66c82d74fdaf07c75d56db339cf3491364</SHA1><branch><SHA1>6df43e66c82d74fdaf07c75d56db339cf3491364</SHA1><name>refs/remotes/origin/6.3.x</name></branch></revision></refsremotesorigin6.3.x><refsremotesorigin6.4.x _class='hudson.plugins.git.util.Build'><buildNumber>571</buildNumber><marked><SHA1>50d31f738f19b3d7b37a86554870383fa9d856e2</SHA1><branch><SHA1>50d31f738f19b3d7b37a86554870383fa9d856e2</SHA1><name>refs/remotes/origin/6.4.x</name></branch></marked><revision><SHA1>50d31f738f19b3d7b37a86554870383fa9d856e2</SHA1><branch><SHA1>50d31f738f19b3d7b37a86554870383fa9d856e2</SHA1><name>refs/remotes/origin/6.4.x</name></branch></revision></refsremotesorigin6.4.x><refsremotesorigin6.1.x _class='hudson.plugins.git.util.Build'><buildNumber>43</buildNumber><marked><SHA1>a3e9b3a1a829e2b076e72afa8bf8da6253ba6b31</SHA1><branch><SHA1>a3e9b3a1a829e2b076e72afa8bf8da6253ba6b31</SHA1><name>refs/remotes/origin/6.1.x</name></branch></marked><revision><SHA1>a3e9b3a1a829e2b076e72afa8bf8da6253ba6b31</SHA1><branch><SHA1>a3e9b3a1a829e2b076e72afa8bf8da6253ba6b31</SHA1><name>refs/remotes/origin/6.1.x</name></branch></revision></refsremotesorigin6.1.x></buildsByBranchName><lastBuiltRevision><SHA1>50d31f738f19b3d7b37a86554870383fa9d856e2</SHA1><branch><SHA1>50d31f738f19b3d7b37a86554870383fa9d856e2</SHA1><name>refs/remotes/origin/6.4.x</name></branch></lastBuiltRevision><remoteUrl>https://github.com/Silverpeas/Silverpeas-Core</remoteUrl><scmName></scmName></action><action _class='hudson.plugins.git.util.BuildData'><buildsByBranchName><refsremotesorigin6.2.x _class='hudson.plugins.git.util.Build'><buildNumber>179</buildNumber><marked><SHA1>6976f0d418d1eb565dded101d00140960944e6aa</SHA1><branch><SHA1>6976f0d418d1eb565dded101d00140960944e6aa</SHA1><name>refs/remotes/origin/6.2.x</name></branch></marked><revision><SHA1>6976f0d418d1eb565dded101d00140960944e6aa</SHA1><branch><SHA1>6976f0d418d1eb565dded101d00140960944e6aa</SHA1><name>refs/remotes/origin/6.2.x</name></branch></revision></refsremotesorigin6.2.x><refsremotesorigin6.3.x _class='hudson.plugins.git.util.Build'><buildNumber>302</buildNumber><marked><SHA1>f1c18f5b16ecf085b04a36a636aa4aa26ec5d773</SHA1><branch><SHA1>f1c18f5b16ecf085b04a36a636aa4aa26ec5d773</SHA1><name>refs/remotes/origin/6.3.x</name></branch></marked><revision><SHA1>f1c18f5b16ecf085b04a36a636aa4aa26ec5d773</SHA1><branch><SHA1>f1c18f5b16ecf085b04a36a636aa4aa26ec5d773</SHA1><name>refs/remotes/origin/6.3.x</name></branch></revision></refsremotesorigin6.3.x><refsremotesorigin6.4.x _class='hudson.plugins.git.util.Build'><buildNumber>571</buildNumber><marked><SHA1>de9cf8606c9910989890a6d004cd47a8e2f611ca</SHA1><branch><SHA1>de9cf8606c9910989890a6d004cd47a8e2f611ca</SHA1><name>refs/remotes/origin/6.4.x</name></branch></marked><revision><SHA1>de9cf8606c9910989890a6d004cd47a8e2f611ca</SHA1><branch><SHA1>de9cf8606c9910989890a6d004cd47a8e2f611ca</SHA1><name>refs/remotes/origin/6.4.x</name></branch></revision></refsremotesorigin6.4.x><refsremotesorigin6.1.x _class='hudson.plugins.git.util.Build'><buildNumber>43</buildNumber><marked><SHA1>9dbcbf90b830646ccd42fb388d09dbe09ecea4e6</SHA1><branch><SHA1>9dbcbf90b830646ccd42fb388d09dbe09ecea4e6</SHA1><name>refs/remotes/origin/6.1.x</name></branch></marked><revision><SHA1>9dbcbf90b830646ccd42fb388d09dbe09ecea4e6</SHA1><branch><SHA1>9dbcbf90b830646ccd42fb388d09dbe09ecea4e6</SHA1><name>refs/remotes/origin/6.1.x</name></branch></revision></refsremotesorigin6.1.x></buildsByBranchName><lastBuiltRevision><SHA1>de9cf8606c9910989890a6d004cd47a8e2f611ca</SHA1><branch><SHA1>de9cf8606c9910989890a6d004cd47a8e2f611ca</SHA1><name>refs/remotes/origin/6.4.x</name></branch></lastBuiltRevision><remoteUrl>https://github.com/Silverpeas/Silverpeas-Components</remoteUrl><scmName></scmName></action><action _class='hudson.plugins.git.util.BuildData'><buildsByBranchName><refsremotesorigin6.2.x _class='hudson.plugins.git.util.Build'><buildNumber>179</buildNumber><marked><SHA1>b3b8a633d5a98083849becc7464aebbca4218501</SHA1><branch><SHA1>b3b8a633d5a98083849becc7464aebbca4218501</SHA1><name>refs/remotes/origin/6.2.x</name></branch></marked><revision><SHA1>b3b8a633d5a98083849becc7464aebbca4218501</SHA1><branch><SHA1>b3b8a633d5a98083849becc7464aebbca4218501</SHA1><name>refs/remotes/origin/6.2.x</name></branch></revision></refsremotesorigin6.2.x><refsremotesorigin6.3.x _class='hudson.plugins.git.util.Build'><buildNumber>302</buildNumber><marked><SHA1>586ebdd23e10f812e41a52cbf1a3a7f4a81fe924</SHA1><branch><SHA1>586ebdd23e10f812e41a52cbf1a3a7f4a81fe924</SHA1><name>refs/remotes/origin/6.3.x</name></branch></marked><revision><SHA1>586ebdd23e10f812e41a52cbf1a3a7f4a81fe924</SHA1><branch><SHA1>586ebdd23e10f812e41a52cbf1a3a7f4a81fe924</SHA1><name>refs/remotes/origin/6.3.x</name></branch></revision></refsremotesorigin6.3.x><refsremotesorigin6.4.x _class='hudson.plugins.git.util.Build'><buildNumber>571</buildNumber><marked><SHA1>f105160616b668c112072a2f4714b531c52c98bc</SHA1><branch><SHA1>f105160616b668c112072a2f4714b531c52c98bc</SHA1><name>refs/remotes/origin/6.4.x</name></branch></marked><revision><SHA1>f105160616b668c112072a2f4714b531c52c98bc</SHA1><branch><SHA1>f105160616b668c112072a2f4714b531c52c98bc</SHA1><name>refs/remotes/origin/6.4.x</name></branch></revision></refsremotesorigin6.4.x><refsremotesorigin6.1.x _class='hudson.plugins.git.util.Build'><buildNumber>43</buildNumber><marked><SHA1>070793013d99eb148b16b15d6a191b20b72bc82c</SHA1><branch><SHA1>070793013d99eb148b16b15d6a191b20b72bc82c</SHA1><name>refs/remotes/origin/6.1.x</name></branch></marked><revision><SHA1>070793013d99eb148b16b15d6a191b20b72bc82c</SHA1><branch><SHA1>070793013d99eb148b16b15d6a191b20b72bc82c</SHA1><name>refs/remotes/origin/6.1.x</name></branch></revision></refsremotesorigin6.1.x></buildsByBranchName><lastBuiltRevision><SHA1>f105160616b668c112072a2f4714b531c52c98bc</SHA1><branch><SHA1>f105160616b668c112072a2f4714b531c52c98bc</SHA1><name>refs/remotes/origin/6.4.x</name></branch></lastBuiltRevision><remoteUrl>https://github.com/Silverpeas/Silverpeas-Looks</remoteUrl><scmName></scmName></action><action _class='hudson.plugins.git.util.BuildData'><buildsByBranchName><refsremotesorigin6.2.x _class='hudson.plugins.git.util.Build'><buildNumber>179</buildNumber><marked><SHA1>abe99f69032413c083fb9ee7a98afc1e2ab5114d</SHA1><branch><SHA1>abe99f69032413c083fb9ee7a98afc1e2ab5114d</SHA1><name>refs/remotes/origin/6.2.x</name></branch></marked><revision><SHA1>abe99f69032413c083fb9ee7a98afc1e2ab5114d</SHA1><branch><SHA1>abe99f69032413c083fb9ee7a98afc1e2ab5114d</SHA1><name>refs/remotes/origin/6.2.x</name></branch></revision></refsremotesorigin6.2.x><refsremotesorigin6.3.x _class='hudson.plugins.git.util.Build'><buildNumber>302</buildNumber><marked><SHA1>146430cd63566b3be410c8dd534faa57033583b3</SHA1><branch><SHA1>146430cd63566b3be410c8dd534faa57033583b3</SHA1><name>refs/remotes/origin/6.3.x</name></branch></marked><revision><SHA1>146430cd63566b3be410c8dd534faa57033583b3</SHA1><branch><SHA1>146430cd63566b3be410c8dd534faa57033583b3</SHA1><name>refs/remotes/origin/6.3.x</name></branch></revision></refsremotesorigin6.3.x><refsremotesorigin6.4.x _class='hudson.plugins.git.util.Build'><buildNumber>571</buildNumber><marked><SHA1>f9a3cc8ddfdefbb340e23594a0d441da1d2cd613</SHA1><branch><SHA1>f9a3cc8ddfdefbb340e23594a0d441da1d2cd613</SHA1><name>refs/remotes/origin/6.4.x</name></branch></marked><revision><SHA1>f9a3cc8ddfdefbb340e23594a0d441da1d2cd613</SHA1><branch><SHA1>f9a3cc8ddfdefbb340e23594a0d441da1d2cd613</SHA1><name>refs/remotes/origin/6.4.x</name></branch></revision></refsremotesorigin6.4.x><refsremotesorigin6.1.x _class='hudson.plugins.git.util.Build'><buildNumber>43</buildNumber><marked><SHA1>62ef5e63f545c1d332fb8e528897aff1fac54150</SHA1><branch><SHA1>62ef5e63f545c1d332fb8e528897aff1fac54150</SHA1><name>refs/remotes/origin/6.1.x</name></branch></marked><revision><SHA1>62ef5e63f545c1d332fb8e528897aff1fac54150</SHA1><branch><SHA1>62ef5e63f545c1d332fb8e528897aff1fac54150</SHA1><name>refs/remotes/origin/6.1.x</name></branch></revision></refsremotesorigin6.1.x></buildsByBranchName><lastBuiltRevision><SHA1>f9a3cc8ddfdefbb340e23594a0d441da1d2cd613</SHA1><branch><SHA1>f9a3cc8ddfdefbb340e23594a0d441da1d2cd613</SHA1><name>refs/remotes/origin/6.4.x</name></branch></lastBuiltRevision><remoteUrl>https://github.com/Silverpeas/Silverpeas-Setup</remoteUrl><scmName></scmName></action><action _class='hudson.plugins.git.util.BuildData'><buildsByBranchName><refsremotesorigin6.2.x _class='hudson.plugins.git.util.Build'><buildNumber>179</buildNumber><marked><SHA1>c96d415a32db2f558555695b382b89c11ac347be</SHA1><branch><SHA1>c96d415a32db2f558555695b382b89c11ac347be</SHA1><name>refs/remotes/origin/6.2.x</name></branch></marked><revision><SHA1>c96d415a32db2f558555695b382b89c11ac347be</SHA1><branch><SHA1>c96d415a32db2f558555695b382b89c11ac347be</SHA1><name>refs/remotes/origin/6.2.x</name></branch></revision></refsremotesorigin6.2.x><refsremotesorigin6.3.x _class='hudson.plugins.git.util.Build'><buildNumber>302</buildNumber><marked><SHA1>10719018413e414cfa70c0f64a945a72670797f4</SHA1><branch><SHA1>10719018413e414cfa70c0f64a945a72670797f4</SHA1><name>refs/remotes/origin/6.3.x</name></branch></marked><revision><SHA1>10719018413e414cfa70c0f64a945a72670797f4</SHA1><branch><SHA1>10719018413e414cfa70c0f64a945a72670797f4</SHA1><name>refs/remotes/origin/6.3.x</name></branch></revision></refsremotesorigin6.3.x><refsremotesorigin6.4.x _class='hudson.plugins.git.util.Build'><buildNumber>571</buildNumber><marked><SHA1>4c911d0c826d86eae553a296dd6f65961fc161ae</SHA1><branch><SHA1>4c911d0c826d86eae553a296dd6f65961fc161ae</SHA1><name>refs/remotes/origin/6.4.x</name></branch></marked><revision><SHA1>4c911d0c826d86eae553a296dd6f65961fc161ae</SHA1><branch><SHA1>4c911d0c826d86eae553a296dd6f65961fc161ae</SHA1><name>refs/remotes/origin/6.4.x</name></branch></revision></refsremotesorigin6.4.x><refsremotesorigin6.1.x _class='hudson.plugins.git.util.Build'><buildNumber>43</buildNumber><marked><SHA1>2c1de09b276e4aa8622563451ebd70a4f24759ce</SHA1><branch><SHA1>2c1de09b276e4aa8622563451ebd70a4f24759ce</SHA1><name>refs/remotes/origin/6.1.x</name></branch></marked><revision><SHA1>2c1de09b276e4aa8622563451ebd70a4f24759ce</SHA1><branch><SHA1>2c1de09b276e4aa8622563451ebd70a4f24759ce</SHA1><name>refs/remotes/origin/6.1.x</name></branch></revision></refsremotesorigin6.1.x></buildsByBranchName><lastBuiltRevision><SHA1>4c911d0c826d86eae553a296dd6f65961fc161ae</SHA1><branch><SHA1>4c911d0c826d86eae553a296dd6f65961fc161ae</SHA1><name>refs/remotes/origin/6.4.x</name></branch></lastBuiltRevision><remoteUrl>https://github.com/Silverpeas/Silverpeas-Distribution</remoteUrl><scmName></scmName></action><action _class='hudson.plugins.git.util.BuildData'><buildsByBranchName><refsremotesorigin6.2.x _class='hudson.plugins.git.util.Build'><buildNumber>179</buildNumber><marked><SHA1>1bdb8f99972aa96dacfc6d8775a7364ab6e845c2</SHA1><branch><SHA1>1bdb8f99972aa96dacfc6d8775a7364ab6e845c2</SHA1><name>refs/remotes/origin/6.2.x</name></branch></marked><revision><SHA1>1bdb8f99972aa96dacfc6d8775a7364ab6e845c2</SHA1><branch><SHA1>1bdb8f99972aa96dacfc6d8775a7364ab6e845c2</SHA1><name>refs/remotes/origin/6.2.x</name></branch></revision></refsremotesorigin6.2.x><refsremotesorigin6.3.x _class='hudson.plugins.git.util.Build'><buildNumber>302</buildNumber><marked><SHA1>e6cf90efb933ea1d65558af1cade3056ac4b6462</SHA1><branch><SHA1>e6cf90efb933ea1d65558af1cade3056ac4b6462</SHA1><name>refs/remotes/origin/6.3.x</name></branch></marked><revision><SHA1>e6cf90efb933ea1d65558af1cade3056ac4b6462</SHA1><branch><SHA1>e6cf90efb933ea1d65558af1cade3056ac4b6462</SHA1><name>refs/remotes/origin/6.3.x</name></branch></revision></refsremotesorigin6.3.x><refsremotesorigin6.4.x _class='hudson.plugins.git.util.Build'><buildNumber>571</buildNumber><marked><SHA1>27fc17db8fc8e443cd002cec7d78fbad61804ec8</SHA1><branch><SHA1>27fc17db8fc8e443cd002cec7d78fbad61804ec8</SHA1><name>refs/remotes/origin/6.4.x</name></branch></marked><revision><SHA1>27fc17db8fc8e443cd002cec7d78fbad61804ec8</SHA1><branch><SHA1>27fc17db8fc8e443cd002cec7d78fbad61804ec8</SHA1><name>refs/remotes/origin/6.4.x</name></branch></revision></refsremotesorigin6.4.x><refsremotesorigin6.1.x _class='hudson.plugins.git.util.Build'><buildNumber>43</buildNumber><marked><SHA1>64a1ed5c344bf6e81820366b63120c460193579c</SHA1><branch><SHA1>64a1ed5c344bf6e81820366b63120c460193579c</SHA1><name>refs/remotes/origin/6.1.x</name></branch></marked><revision><SHA1>64a1ed5c344bf6e81820366b63120c460193579c</SHA1><branch><SHA1>64a1ed5c344bf6e81820366b63120c460193579c</SHA1><name>refs/remotes/origin/6.1.x</name></branch></revision></refsremotesorigin6.1.x></buildsByBranchName><lastBuiltRevision><SHA1>27fc17db8fc8e443cd002cec7d78fbad61804ec8</SHA1><branch><SHA1>27fc17db8fc8e443cd002cec7d78fbad61804ec8</SHA1><name>refs/remotes/origin/6.4.x</name></branch></lastBuiltRevision><remoteUrl>https://github.com/Silverpeas/Silverpeas-Assembly</remoteUrl><scmName></scmName></action><action></action><action _class='hudson.plugins.sonar.action.SonarAnalysisAction'><ceTaskId>AaD2JBITnW7s-NNcLCz7</ceTaskId><installationName>Silverpeas SonarCloud</installationName><installationUrl>https://sonarcloud.io</installationUrl><new>true</new><serverUrl>https://sonarcloud.io</serverUrl><skipped>false</skipped><sonarqubeDashboardUrl>https://sonarcloud.io/dashboard?id=Silverpeas_Silverpeas-Core2&amp;branch=6.4.x</sonarqubeDashboardUrl></action><action></action><action></action><action _class='hudson.plugins.sonar.action.SonarAnalysisAction'><ceTaskId>AaD2RaVYkj6CGoBn8Dna</ceTaskId><installationName>Silverpeas SonarCloud</installationName><installationUrl>https://sonarcloud.io</installationUrl><new>true</new><serverUrl>https://sonarcloud.io</serverUrl><skipped>false</skipped><sonarqubeDashboardUrl>https://sonarcloud.io/dashboard?id=Silverpeas_Silverpeas-Components&amp;branch=6.4.x</sonarqubeDashboardUrl></action><action></action><action></action><action></action><action></action><action></action><action _class='hudson.plugins.sonar.action.SonarBuildBadgeAction'></action><action></action><action _class='org.jenkinsci.plugins.displayurlapi.actions.RunDisplayAction'></action><action _class='org.jenkinsci.plugins.pipeline.modeldefinition.actions.RestartDeclarativePipelineAction'></action><action></action><action _class='org.jenkinsci.plugins.workflow.job.views.FlowGraphAction'></action><action></action><action></action><artifact><displayPath>build.yaml</displayPath><fileName>build.yaml</fileName><relativePath>target/build.yaml</relativePath></artifact><building>false</building><displayName>6.4.8-build261001</displayName><duration>9118224</duration><estimatedDuration>5497799</estimatedDuration><fullDisplayName>Silverpeas_Stable_AutoDeploy 6.4.8-build261001</fullDisplayName><id>571</id><keepLog>false</keepLog><number>571</number><queueId>64011</queueId><result>SUCCESS</result><timestamp>1790829960596</timestamp><url>https://integration.silverpeas.org/jenkins/job/Silverpeas_Stable_AutoDeploy/571/</url><changeSet _class='hudson.plugins.git.GitChangeSetList'><item _class='hudson.plugins.git.GitChangeSet'><affectedPath>core-web/src/main/java/org/silverpeas/core/web/filter/MassiveWebSecurityFilter.java</affectedPath><affectedPath>core-web-test/src/main/java/org/silverpeas/web/test/stub/TestHttpRequest.java</affectedPath><affectedPath>core-web/src/integration-test/java/org/silverpeas/core/web/filter/MassiveWebSecurityFilterOnReportedXssIT.java</affectedPath><commitId>cbca010a1bf431ccce251585dcf892700d9f4272</commitId><timestamp>1790599035000</timestamp><author><absoluteUrl>https://integration.silverpeas.org/jenkins/user/mmoquillon</absoluteUrl><fullName>Miguel Moquillon</fullName></author><authorEmail>miguel.moquillon@gmail.com</authorEmail><comment>Harden the detection of the event callbacks against the vulnerabilities #1458, #1459 and #1460

(GitHub issues, reported against 6.4.6)

The three reported stored XSS rely on an event callback attribute carried by an
element the browser fails to load on purpose. Such a declaration was detected by
the \s+on\w+\s*= pattern, which expects a whitespace before the attribute name.
According to the HTML tokenizer, an attribute name is also expected right after
the closing quote of the previous attribute value (a
missing-whitespace-between-attributes parse error, whose recovery is mandated by
the specification) and right after a solidus. So the following did declare an
onerror callback the browsers do run, while going through the filter:

  &lt;img src="x"onerror=alert(1)&gt;

The pattern now accepts these separators as well.

Note this filter is an input guard, not an output encoding: it narrows the
reachability of the three flaws but it doesn't fix the rendering code itself.

MassiveWebSecurityFilterOnReportedXssIT covers the payloads of the three reports
on their actual endpoints and parameters, including when they are submitted as
multipart/form-data streams as the genuine forms do. It also delimits the
multipart exemption, which applies to the webPages component only.

TestHttpRequest.getContentType() returned null whatever the headers set on the
stub, which made the multipart branch untestable.

Co-Authored-By: Claude Opus 5 (1M context) &lt;noreply@anthropic.com&gt;
</comment><date>2026-09-28 14:37:15 +0200</date><id>cbca010a1bf431ccce251585dcf892700d9f4272</id><msg>Harden the detection of the event callbacks against the vulnerabilities #1458, #1459 and #1460</msg><path><editType>edit</editType><file>core-web-test/src/main/java/org/silverpeas/web/test/stub/TestHttpRequest.java</file></path><path><editType>add</editType><file>core-web/src/integration-test/java/org/silverpeas/core/web/filter/MassiveWebSecurityFilterOnReportedXssIT.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/web/filter/MassiveWebSecurityFilter.java</file></path></item><item _class='hudson.plugins.git.GitChangeSet'><affectedPath>core-war/src/main/webapp/defaultLoginQuestion.jsp</affectedPath><commitId>b8e6d6bb35fda9a02280c287662a61e7683c275a</commitId><timestamp>1790599035000</timestamp><author><absoluteUrl>https://integration.silverpeas.org/jenkins/user/mmoquillon</absoluteUrl><fullName>Miguel Moquillon</fullName></author><authorEmail>miguel.moquillon@gmail.com</authorEmail><comment>Fix vulnerability #1458

(GitHub issue, reported against 6.4.6)

The login question, which any authenticated user sets from their profile, was
printed raw by a JSP scriptlet on the password reminder page, an anonymous one.
Any script stored there was then run in the browser of every visitor of that
page, without any login required from them. The answer to that question, itself
a credential, is asked on the very same page.

The value is now HTML encoded on output, through a c:out tag. Doing so on the
rendering side rather than on the writing one closes both the ways the field is
fed: MyProfilRequestRouter, which the report points at, but also
ValidationQuestionHandler, which stores the question of the ValidateQuestion
function with no more filtering. It also neutralizes the values already stored.

The login of the hidden field below is encoded as well. It comes from a lookup
in the database and not from the request parameter, so exploiting it would
require a login holding a quote, but the encoding costs nothing here.

Co-Authored-By: Claude Opus 5 (1M context) &lt;noreply@anthropic.com&gt;
</comment><date>2026-09-28 14:37:15 +0200</date><id>b8e6d6bb35fda9a02280c287662a61e7683c275a</id><msg>Fix vulnerability #1458</msg><path><editType>edit</editType><file>core-war/src/main/webapp/defaultLoginQuestion.jsp</file></path></item><item _class='hudson.plugins.git.GitChangeSet'><affectedPath>core-web/src/main/java/org/silverpeas/core/web/filter/IFrameChecker.java</affectedPath><affectedPath>core-library/src/main/java/org/silverpeas/core/contribution/content/wysiwyg/service/directive/SanitizeForRenderingDirective.java</affectedPath><affectedPath>core-services/importExport/src/main/java/org/silverpeas/core/importexport/report/HtmlExportPublicationGenerator.java</affectedPath><affectedPath>core-configuration/src/main/config/properties/org/silverpeas/util/security.properties</affectedPath><affectedPath>core-library/src/main/java/org/silverpeas/core/contribution/content/form/displayers/WysiwygFCKFieldDisplayer.java</affectedPath><affectedPath>core-library/src/integration-test/java/org/silverpeas/core/test/WarBuilder4LibCore.java</affectedPath><affectedPath>core-library/src/integration-test/resources/org/silverpeas/util/security.properties</affectedPath><affectedPath>core-library/src/main/java/org/silverpeas/core/contribution/content/wysiwyg/service/WysiwygContentRenderer.java</affectedPath><affectedPath>core-api/src/main/java/org/silverpeas/core/security/html/EmbeddedSourceValidator.java</affectedPath><affectedPath>core-library/src/integration-test/java/org/silverpeas/core/contribution/content/wysiwyg/service/WysiwygControllerIT.java</affectedPath><affectedPath>core-library/src/test/java/org/silverpeas/core/contribution/content/wysiwyg/service/WysiwygContentTransformerTest.java</affectedPath><affectedPath>core-api/src/main/java/org/silverpeas/core/util/security/SecuritySettings.java</affectedPath><affectedPath>core-services/importExport/src/main/java/org/silverpeas/core/importexport/control/PublicationsTypeManager.java</affectedPath><affectedPath>core-library/src/main/java/org/silverpeas/core/contribution/content/wysiwyg/service/WysiwygContentTransformer.java</affectedPath><commitId>661dad84ee2e8251e0a0291c75876b2f91db5aef</commitId><timestamp>1790599035000</timestamp><author><absoluteUrl>https://integration.silverpeas.org/jenkins/user/mmoquillon</absoluteUrl><fullName>Miguel Moquillon</fullName></author><authorEmail>miguel.moquillon@gmail.com</authorEmail><comment>Fix vulnerability #1459

(GitHub issue, reported against 6.4.6)

The WYSIWYG content of a form field was written into the response as raw HTML by
WysiwygFCKFieldDisplayer, so any script stored by the writer of a whitePages
card was run in the browser of every user viewing it. The same held for the
content of a publication, rendered by WysiwygContentRenderer, and for the two
export paths, none of which was reported.

Such a content is sanitized now, by the new SanitizeForRenderingDirective.
Unlike SanitizeDirective, which keeps only a restricted set of safe elements and
is left untouched for the contents extracted out of Silverpeas, this one keeps
the content as it is and drops only what can act on the visitor's browser:

- the elements able to run code or to take over the document, with their
  content;
- the event callback attributes, whatever the element carrying them;
- the attributes referring a URL with a scripting scheme;
- the iframes and the media whose source isn't allowed.

This is deliberate: the WYSIWYG editor is set up to accept any content
(config.allowedContent = true in silverconfig.js), so an allow list applied at
rendering time would be narrower than what the users are entitled to write. It
would in particular have dropped the media produced by the video and html5audio
plugins and the rel attribute the userzoom and identitycard ones rely upon.

The parsing is delegated to the HTML tokenizer of the OWASP sanitizer, so the
content is read the way a browser reads it and the dropping can't be dodged by
playing with the HTML syntax.

The rule deciding whether the source of an iframe is allowed moves to the new
EmbeddedSourceValidator class, so that the filtering of the incoming requests
and this sanitization agree on it. It now serves the media as well, through the
new security.external.media.hosts.allowed property. That property is shipped
with the * value, which allows any host and hence preserves the behaviour of the
previous versions; setting it empty restricts the media to the ones Silverpeas
hosts itself. The inlined images are kept whatever it is, being carried by the
content itself.

The mail path is deliberately left out: its images are referred by cid URLs,
which such a sanitization drops, and its content isn't rendered in the
Silverpeas origin anyway.

Co-Authored-By: Claude Opus 5 (1M context) &lt;noreply@anthropic.com&gt;
</comment><date>2026-09-28 14:37:15 +0200</date><id>661dad84ee2e8251e0a0291c75876b2f91db5aef</id><msg>Fix vulnerability #1459</msg><path><editType>edit</editType><file>core-services/importExport/src/main/java/org/silverpeas/core/importexport/control/PublicationsTypeManager.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/web/filter/IFrameChecker.java</file></path><path><editType>edit</editType><file>core-configuration/src/main/config/properties/org/silverpeas/util/security.properties</file></path><path><editType>add</editType><file>core-library/src/integration-test/resources/org/silverpeas/util/security.properties</file></path><path><editType>edit</editType><file>core-library/src/integration-test/java/org/silverpeas/core/test/WarBuilder4LibCore.java</file></path><path><editType>edit</editType><file>core-services/importExport/src/main/java/org/silverpeas/core/importexport/report/HtmlExportPublicationGenerator.java</file></path><path><editType>edit</editType><file>core-library/src/main/java/org/silverpeas/core/contribution/content/wysiwyg/service/WysiwygContentRenderer.java</file></path><path><editType>edit</editType><file>core-library/src/main/java/org/silverpeas/core/contribution/content/form/displayers/WysiwygFCKFieldDisplayer.java</file></path><path><editType>add</editType><file>core-library/src/main/java/org/silverpeas/core/contribution/content/wysiwyg/service/directive/SanitizeForRenderingDirective.java</file></path><path><editType>edit</editType><file>core-library/src/integration-test/java/org/silverpeas/core/contribution/content/wysiwyg/service/WysiwygControllerIT.java</file></path><path><editType>edit</editType><file>core-library/src/test/java/org/silverpeas/core/contribution/content/wysiwyg/service/WysiwygContentTransformerTest.java</file></path><path><editType>edit</editType><file>core-library/src/main/java/org/silverpeas/core/contribution/content/wysiwyg/service/WysiwygContentTransformer.java</file></path><path><editType>add</editType><file>core-api/src/main/java/org/silverpeas/core/security/html/EmbeddedSourceValidator.java</file></path><path><editType>edit</editType><file>core-api/src/main/java/org/silverpeas/core/util/security/SecuritySettings.java</file></path></item><item _class='hudson.plugins.git.GitChangeSet'><affectedPath>core-library/src/main/java/org/silverpeas/core/util/HttpUtil.java</affectedPath><commitId>5ebb4137a1e0058436d4e39ec80ec42a6b9c5f91</commitId><timestamp>1790599035000</timestamp><author><absoluteUrl>https://integration.silverpeas.org/jenkins/user/mmoquillon</absoluteUrl><fullName>Miguel Moquillon</fullName></author><authorEmail>miguel.moquillon@gmail.com</authorEmail><comment>Fix vulnerability #1461

(GitHub issue, reported against 6.4.6)

Let the callers of HttpUtil complete the HTTP client.

Fixing that vulnerability requires the gallery component to request the image of
a watermark with a connection timeout and without following the redirections,
the latter being able to escape the verification of the address being requested.

httpClientBuilder() gives the builder of the HTTP client, already configured
with the proxy of Silverpeas, so that such a caller can complete the
configuration without having to duplicate that of the proxy. httpClient() now
delegates to it and is unchanged for its own callers.

Co-Authored-By: Claude Opus 5 &lt;noreply@anthropic.com&gt;
</comment><date>2026-09-28 14:37:15 +0200</date><id>5ebb4137a1e0058436d4e39ec80ec42a6b9c5f91</id><msg>Fix vulnerability #1461</msg><path><editType>edit</editType><file>core-library/src/main/java/org/silverpeas/core/util/HttpUtil.java</file></path></item><item _class='hudson.plugins.git.GitChangeSet'><affectedPath>core-war/src/main/webapp/util/javaScript/silverpeas-fileUpload.js</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/web/filter/MassiveWebSecurityFilter.java</affectedPath><affectedPath>core-web/src/integration-test/java/org/silverpeas/core/web/filter/MassiveWebSecurityFilterOnReportedXssIT.java</affectedPath><commitId>2ad38c6954d3170053da74aea7d4f47a06404d63</commitId><timestamp>1790599035000</timestamp><author><absoluteUrl>https://integration.silverpeas.org/jenkins/user/mmoquillon</absoluteUrl><fullName>Miguel Moquillon</fullName></author><authorEmail>miguel.moquillon@gmail.com</authorEmail><comment>Fix the vulnerabilities CVE-2026-78738 and CVE-2026-78741

Both report a stored XSS through the name of an uploaded file, one from the
document management and the other from the image upload of the WYSIWYG editor.
They share their cause: the name is written as an HTML content by the upload
widget, whereas it is carried by the request and escaped on the sending side
only, which protects from nothing as a request can be forged.

The name is now set as a text. Note the formatted size which followed it was
already not displayed, html() taking a single argument, so the display is left
unchanged.

A scripting scheme given as the value of an attribute is detected as well by
MassiveWebSecurityFilter. Such a declaration holds no on prefix and was
therefore going through, and the colon introducing it is accepted written as
the character itself or as any of the HTML entities standing for it, as the
reported payload uses "javascript&amp;colon;". The data scheme is deliberately left
out: the contents do embed their inlined images with it.
</comment><date>2026-09-28 14:37:15 +0200</date><id>2ad38c6954d3170053da74aea7d4f47a06404d63</id><msg>Fix the vulnerabilities CVE-2026-78738 and CVE-2026-78741</msg><path><editType>edit</editType><file>core-war/src/main/webapp/util/javaScript/silverpeas-fileUpload.js</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/web/filter/MassiveWebSecurityFilter.java</file></path><path><editType>edit</editType><file>core-web/src/integration-test/java/org/silverpeas/core/web/filter/MassiveWebSecurityFilterOnReportedXssIT.java</file></path></item><item _class='hudson.plugins.git.GitChangeSet'><affectedPath>core-library/src/integration-test/resources/org/silverpeas/core/node/dao/nodes-sorting-dataset.sql</affectedPath><affectedPath>core-library/src/main/java/org/silverpeas/core/node/dao/NodeDAO.java</affectedPath><affectedPath>core-library/src/integration-test/java/org/silverpeas/core/node/dao/NodeSortingIT.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/node/ListNodeResource.java</affectedPath><commitId>baa73a5b26b3e593c802c659e6d67799bb92a400</commitId><timestamp>1790599035000</timestamp><author><absoluteUrl>https://integration.silverpeas.org/jenkins/user/mmoquillon</absoluteUrl><fullName>Miguel Moquillon</fullName></author><authorEmail>miguel.moquillon@gmail.com</authorEmail><comment>Sort only the nodes of the component instance being administrated

The sorting of the nodes was granted against the component instance referred by
the URL of the REST service, whereas the nodes to sort were taken from the
request body, each of them carrying the component instance it belongs to. An
administrator of any instance could hence ask to sort the nodes of another one.

The nodes are now identified within the instance of the URL, the one the
authorization has been checked against. Taking that instance from the body
brought nothing: the sorting applies by nature to the instance administrated.

That wasn't enough though. NodeDAO was updating the order of a node by its
identifier only, whereas such an identifier isn't unique by itself: the root
node of every component instance is numbered 0, and the ones below it can bear
the same numbers from an instance to another. So the instance of the node is
now part of the criteria. Beyond the authorization, this was a defect on its
own: sorting the nodes of an instance was renumbering the nodes of the other
ones bearing the same identifiers, whoever asked for that sorting.

NodeSortingIT covers the sorting of the nodes of an instance and the isolation
of the other instances from it, in both directions.

Co-Authored-By: Claude Opus 5 &lt;noreply@anthropic.com&gt;
</comment><date>2026-09-28 14:37:15 +0200</date><id>baa73a5b26b3e593c802c659e6d67799bb92a400</id><msg>Sort only the nodes of the component instance being administrated</msg><path><editType>add</editType><file>core-library/src/integration-test/resources/org/silverpeas/core/node/dao/nodes-sorting-dataset.sql</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/node/ListNodeResource.java</file></path><path><editType>add</editType><file>core-library/src/integration-test/java/org/silverpeas/core/node/dao/NodeSortingIT.java</file></path><path><editType>edit</editType><file>core-library/src/main/java/org/silverpeas/core/node/dao/NodeDAO.java</file></path></item><item _class='hudson.plugins.git.GitChangeSet'><affectedPath>core-library/src/main/java/org/silverpeas/core/contribution/content/wysiwyg/service/directive/SanitizeForRenderingDirective.java</affectedPath><commitId>e43a2cc2b84df2a3c699cc7d0bd7819f04af5c8e</commitId><timestamp>1790599035000</timestamp><author><absoluteUrl>https://integration.silverpeas.org/jenkins/user/mmoquillon</absoluteUrl><fullName>Miguel Moquillon</fullName></author><authorEmail>miguel.moquillon@gmail.com</authorEmail><comment>Take into account sonarcloud feedback
</comment><date>2026-09-28 14:37:15 +0200</date><id>e43a2cc2b84df2a3c699cc7d0bd7819f04af5c8e</id><msg>Take into account sonarcloud feedback</msg><path><editType>edit</editType><file>core-library/src/main/java/org/silverpeas/core/contribution/content/wysiwyg/service/directive/SanitizeForRenderingDirective.java</file></path></item><item _class='hudson.plugins.git.GitChangeSet'><affectedPath>core-configuration/src/main/config/properties/org/silverpeas/util/security.properties</affectedPath><commitId>cc844d33395f7b7d1b1167d15235cf636b534293</commitId><timestamp>1790599249000</timestamp><author><absoluteUrl>https://integration.silverpeas.org/jenkins/user/mmoquillon</absoluteUrl><fullName>Miguel Moquillon</fullName></author><authorEmail>miguel.moquillon@silverpeas.com</authorEmail><comment>Now the parameter security.external.media.hosts.allowed is empty.

This means all hosts out of Silverpeas will be refused in HTML media
tags (video, iframe, img, ...)
</comment><date>2026-09-28 14:40:49 +0200</date><id>cc844d33395f7b7d1b1167d15235cf636b534293</id><msg>Now the parameter security.external.media.hosts.allowed is empty.</msg><path><editType>edit</editType><file>core-configuration/src/main/config/properties/org/silverpeas/util/security.properties</file></path></item><item _class='hudson.plugins.git.GitChangeSet'><affectedPath>core-library/src/main/java/org/silverpeas/core/index/indexing/parser/tika/TikaParser.java</affectedPath><affectedPath>core-library/src/main/java/org/silverpeas/core/index/indexing/model/IndexManager.java</affectedPath><affectedPath>core-library/src/main/java/org/silverpeas/core/index/indexing/parser/Parser.java</affectedPath><commitId>50d31f738f19b3d7b37a86554870383fa9d856e2</commitId><timestamp>1790608560000</timestamp><author><absoluteUrl>https://integration.silverpeas.org/jenkins/user/mmoquillon</absoluteUrl><fullName>Miguel Moquillon</fullName></author><authorEmail>miguel.moquillon@silverpeas.com</authorEmail><comment>Fix bug-15488
</comment><date>2026-09-28 17:16:00 +0200</date><id>50d31f738f19b3d7b37a86554870383fa9d856e2</id><msg>Fix bug-15488</msg><path><editType>edit</editType><file>core-library/src/main/java/org/silverpeas/core/index/indexing/model/IndexManager.java</file></path><path><editType>edit</editType><file>core-library/src/main/java/org/silverpeas/core/index/indexing/parser/tika/TikaParser.java</file></path><path><editType>edit</editType><file>core-library/src/main/java/org/silverpeas/core/index/indexing/parser/Parser.java</file></path></item><kind>git</kind></changeSet><changeSet _class='hudson.plugins.git.GitChangeSetList'><item _class='hudson.plugins.git.GitChangeSet'><affectedPath>forums/forums-war/src/main/webapp/forums/jsp/modifyMessage.jsp</affectedPath><affectedPath>forums/forums-war/src/main/webapp/forums/jsp/viewMessage.jsp</affectedPath><affectedPath>forums/forums-war/src/main/webapp/forums/jsp/editMessageKeywords.jsp</affectedPath><commitId>6d20d3540502e348e7b4716d788dc8eb1425d9b1</commitId><timestamp>1790599054000</timestamp><author><absoluteUrl>https://integration.silverpeas.org/jenkins/user/mmoquillon</absoluteUrl><fullName>Miguel Moquillon</fullName></author><authorEmail>miguel.moquillon@gmail.com</authorEmail><comment>Fix vulnerability #1460

(GitHub issue of Silverpeas-Core, reported against 6.4.6)

The title and the body of a forum message were printed raw by JSP scriptlets on
the thread page, so any script posted by a user of the forum was run in the
browser of every user reading it.

The title is now HTML encoded on output, as the other JSPs of the component
already do through WebEncodeHelper. Two other raw outputs of the title, which
the report doesn't mention, are encoded as well: the one of modifyMessage.jsp,
where the title lands in the value attribute of an input and is hence
exploitable by escaping that attribute, and the one of editMessageKeywords.jsp.

The body is sanitized by the applySanitizeForRenderingDirective directive
introduced in Silverpeas-Core for the vulnerability #1459, which drops what can
act on the visitor's browser while keeping the content as it is.

Note the report also states the title pollutes the title element of the page.
It does appear there, but viewMessage.jsp already prints it through a c:out tag,
so it is encoded and isn't a vector.

Co-Authored-By: Claude Opus 5 (1M context) &lt;noreply@anthropic.com&gt;
</comment><date>2026-09-28 14:37:34 +0200</date><id>6d20d3540502e348e7b4716d788dc8eb1425d9b1</id><msg>Fix vulnerability #1460</msg><path><editType>edit</editType><file>forums/forums-war/src/main/webapp/forums/jsp/viewMessage.jsp</file></path><path><editType>edit</editType><file>forums/forums-war/src/main/webapp/forums/jsp/editMessageKeywords.jsp</file></path><path><editType>edit</editType><file>forums/forums-war/src/main/webapp/forums/jsp/modifyMessage.jsp</file></path></item><item _class='hudson.plugins.git.GitChangeSet'><affectedPath>gallery/gallery-library/src/main/java/org/silverpeas/components/gallery/Watermark.java</affectedPath><affectedPath>gallery/gallery-library/src/test/java/org/silverpeas/components/gallery/WatermarkTest.java</affectedPath><commitId>508c8747e5b8116c0f642aa306a22a8ebb8c0264</commitId><timestamp>1790599054000</timestamp><author><absoluteUrl>https://integration.silverpeas.org/jenkins/user/mmoquillon</absoluteUrl><fullName>Miguel Moquillon</fullName></author><authorEmail>miguel.moquillon@gmail.com</authorEmail><comment>Fix vulnerability #1461

(GitHub issue of Silverpeas-Core, reported against 6.4.6)

The image of a watermark is an instance parameter any manager of the space
holding the gallery can set, and the server requests it as it is, at each media
creation. It could hence be pointed at a service the server keeps for itself.

Such an URL is now verified before being requested: only the HTTP and HTTPS
schemes are handled, and the host must resolve to neither a loopback nor a
link-local address, so that neither the services bound to the server itself nor
the metadata endpoint of a cloud provider can be reached. Every address the host
resolves to is verified, otherwise a host resolving to a forbidden address
beside an allowed one would go through.

The addresses of the private networks of an organization remain reachable on
purpose: they are where the internal resources of an intranet legitimately live,
and no address range can tell them from the internal services one would rather
protect. Only an explicit list of allowed hosts could, which is left to a
further decision.

The request is besides given a timeout and its response is no longer copied
without any bound, both being able to exhaust the resources of the server, and
the redirections are no longer followed as they would escape the verification
above.

Co-Authored-By: Claude Opus 5 &lt;noreply@anthropic.com&gt;
</comment><date>2026-09-28 14:37:34 +0200</date><id>508c8747e5b8116c0f642aa306a22a8ebb8c0264</id><msg>Fix vulnerability #1461</msg><path><editType>add</editType><file>gallery/gallery-library/src/test/java/org/silverpeas/components/gallery/WatermarkTest.java</file></path><path><editType>edit</editType><file>gallery/gallery-library/src/main/java/org/silverpeas/components/gallery/Watermark.java</file></path></item><item _class='hudson.plugins.git.GitChangeSet'><affectedPath>infoLetter/infoLetter-war/src/main/webapp/infoLetter/jsp/previewLetter.jsp</affectedPath><affectedPath>infoLetter/infoLetter-war/src/main/webapp/infoLetter/jsp/headerLetter.jsp</affectedPath><affectedPath>infoLetter/infoLetter-war/src/main/java/org/silverpeas/components/infoletter/servlets/InfoLetterRequestRouter.java</affectedPath><commitId>249c3e5a9115c7c560eae2043b256dddfab53378</commitId><timestamp>1790599054000</timestamp><author><absoluteUrl>https://integration.silverpeas.org/jenkins/user/mmoquillon</absoluteUrl><fullName>Miguel Moquillon</fullName></author><authorEmail>miguel.moquillon@gmail.com</authorEmail><comment>Fix vulnerability #1462 and secure the other writings of the newsletter

(GitHub issue of Silverpeas-Core, reported against 6.4.6)

Publishing an issue of a newsletter changes its state, stamps its publication
date, notifies the subscribers and mails the external ones. It was requested by
a GET, and the synchronizer token is required on a GET only when its URL holds
one of a few keywords, which ValidateParution holds none of. Any logged user
lured into a cross-site visit was hence publishing the issue as themselves.

The publication is now submitted by POST, on which the token is required
whatever the URL, through the formRequest facility which stamps it.

Moreover the endpoint had no role check at all, so any reader of the newsletter
was able to publish an issue and to trigger the mailing, with no luring needed.
Only its publishers and its managers can do so now.

Three other writings, which the report doesn't mention, were exposed the same
way and are secured likewise:
- resetting the content of an issue with its template, which overwrites the
  content being written;
- mailing an issue to oneself and to the managers, which sends the content of an
  issue not published yet and was hence a way for any reader to get a draft.

As EditContent also serves the edition itself, a mere navigation which remains a
GET, the reset is explicitly refused when it isn't requested by POST: submitting
it by POST would otherwise protect nothing, the previous URL remaining
requestable.

Co-Authored-By: Claude Opus 5 &lt;noreply@anthropic.com&gt;
</comment><date>2026-09-28 14:37:34 +0200</date><id>249c3e5a9115c7c560eae2043b256dddfab53378</id><msg>Fix vulnerability #1462 and secure the other writings of the newsletter</msg><path><editType>edit</editType><file>infoLetter/infoLetter-war/src/main/webapp/infoLetter/jsp/previewLetter.jsp</file></path><path><editType>edit</editType><file>infoLetter/infoLetter-war/src/main/java/org/silverpeas/components/infoletter/servlets/InfoLetterRequestRouter.java</file></path><path><editType>edit</editType><file>infoLetter/infoLetter-war/src/main/webapp/infoLetter/jsp/headerLetter.jsp</file></path></item><item _class='hudson.plugins.git.GitChangeSet'><affectedPath>infoLetter/infoLetter-war/src/main/webapp/infoLetter/jsp/listLetterUser.jsp</affectedPath><affectedPath>infoLetter/infoLetter-war/src/main/java/org/silverpeas/components/infoletter/servlets/InfoLetterRequestRouter.java</affectedPath><affectedPath>infoLetter/infoLetter-war/src/main/webapp/infoLetter/jsp/listLetterAdmin.jsp</affectedPath><commitId>da97397bc61edab0e1f7156bdbf315ab64129113</commitId><timestamp>1790599054000</timestamp><author><absoluteUrl>https://integration.silverpeas.org/jenkins/user/mmoquillon</absoluteUrl><fullName>Miguel Moquillon</fullName></author><authorEmail>miguel.moquillon@gmail.com</authorEmail><comment>Fix vulnerabilities #1463

(GitHub issue of Silverpeas-Core, reported against 6.4.6)

The operations on the issues themselves were exposed the same way and are
secured likewise: creating and modifying an issue, and modifying the headers of
the newsletter, were requestable by a GET although their forms are submitted by
POST, the router not caring about the method.

None of the operations of this router had any role check, so any reader was able
to write the content of an issue, to modify the headers of the newsletter, to
delete issues and to read the ones being written. They are now reserved to the
publishers and to the managers, but for the ones on the template and the
deletion of several issues at once, reserved to the managers.

Reading the inlined CSS rendering of an issue is how the readers get it from the
list, so the criterion there isn't the role but the issue itself: it is refused
to them as long as it isn't published.
</comment><date>2026-09-28 14:37:34 +0200</date><id>da97397bc61edab0e1f7156bdbf315ab64129113</id><msg>Fix vulnerabilities #1463</msg><path><editType>edit</editType><file>infoLetter/infoLetter-war/src/main/java/org/silverpeas/components/infoletter/servlets/InfoLetterRequestRouter.java</file></path><path><editType>edit</editType><file>infoLetter/infoLetter-war/src/main/webapp/infoLetter/jsp/listLetterAdmin.jsp</file></path><path><editType>edit</editType><file>infoLetter/infoLetter-war/src/main/webapp/infoLetter/jsp/listLetterUser.jsp</file></path></item><item _class='hudson.plugins.git.GitChangeSet'><affectedPath>kmelia/kmelia-war/src/main/webapp/kmelia/jsp/publicationLinksManager.jsp</affectedPath><affectedPath>kmelia/kmelia-war/src/main/webapp/kmelia/jsp/basket.jsp</affectedPath><affectedPath>kmelia/kmelia-war/src/main/java/org/silverpeas/components/kmelia/servlets/ajax/AjaxOperation.java</affectedPath><affectedPath>kmelia/kmelia-war/src/main/webapp/kmelia/jsp/orderTopics.jsp</affectedPath><affectedPath>kmelia/kmelia-war/src/main/java/org/silverpeas/components/kmelia/servlets/AjaxServlet.java</affectedPath><commitId>217fe3edf581b66e5c9f935e9e367022e86977a6</commitId><timestamp>1790599054000</timestamp><author><absoluteUrl>https://integration.silverpeas.org/jenkins/user/mmoquillon</absoluteUrl><fullName>Miguel Moquillon</fullName></author><authorEmail>miguel.moquillon@gmail.com</authorEmail><comment>Fix vulnerability #1464

(GitHub issue of Silverpeas-Core, reported against 6.4.6)

Loading publications into the clipboard and pasting them under another topic
were requestable by a GET, so any logged user lured into a cross-site visit was
moving publications as themselves.

The AJAX servlet of kmelia answers the GET as the POST, and none of its URLs
holds any of the keywords making the synchronizer token required on a GET. So
none of its operations was protected, including the deletion of publications
which the report takes as protected: its URL does hold the delete keyword, but
the rule applied to this servlet requires in addition the path to hold /jsp/,
which the path of a servlet doesn't.

The operations only reading something are now listed apart, every other one
being taken as writing something so that adding an operation doesn't expose it
by mistake, and a writing operation requested by a GET is refused. That refusal
is performed before the processing, whose catch-all would swallow it.

The user interface already submitted by POST the operations the report points
at, as well as the deletion, the copy and the move of publications: what made
the attack possible is the servlet accepting the GET. Three operations were
still requested by a GET and are now submitted by POST: sorting the topics,
emptying the trash from the basket, and binding a publication to another one.
</comment><date>2026-09-28 14:37:34 +0200</date><id>217fe3edf581b66e5c9f935e9e367022e86977a6</id><msg>Fix vulnerability #1464</msg><path><editType>edit</editType><file>kmelia/kmelia-war/src/main/webapp/kmelia/jsp/basket.jsp</file></path><path><editType>edit</editType><file>kmelia/kmelia-war/src/main/webapp/kmelia/jsp/publicationLinksManager.jsp</file></path><path><editType>edit</editType><file>kmelia/kmelia-war/src/main/java/org/silverpeas/components/kmelia/servlets/AjaxServlet.java</file></path><path><editType>edit</editType><file>kmelia/kmelia-war/src/main/java/org/silverpeas/components/kmelia/servlets/ajax/AjaxOperation.java</file></path><path><editType>edit</editType><file>kmelia/kmelia-war/src/main/webapp/kmelia/jsp/orderTopics.jsp</file></path></item><item _class='hudson.plugins.git.GitChangeSet'><affectedPath>kmelia/kmelia-war/src/main/java/org/silverpeas/components/kmelia/web/KmeliaResource.java</affectedPath><affectedPath>kmelia/kmelia-war/src/test/java/org/silverpeas/components/kmelia/web/KmeliaResourceTest.java</affectedPath><affectedPath>kmelia/kmelia-war/pom.xml</affectedPath><commitId>b7db955aa0a1cdeaf903b52ddce739e32d3836fd</commitId><timestamp>1790599054000</timestamp><author><absoluteUrl>https://integration.silverpeas.org/jenkins/user/mmoquillon</absoluteUrl><fullName>Miguel Moquillon</fullName></author><authorEmail>miguel.moquillon@gmail.com</authorEmail><comment>Fix vulnerability #939

(GitHub issue of Silverpeas-Components, reported against 6.4.6)

Updating a publication was granted against the component instance referred by
the URL, whereas the publication to update was entirely defined by the request
body, which carries both its identifier and its component instance. Any user
could hence rewrite the metadata of any publication of the platform by referring
it in the body, the identifiers being enumerable.

The publication is now refused when it doesn't belong to the instance the
authorization has been checked against. Note the report states a WRITER role is
required: it is not, the authorization of the REST framework only validating the
access to the instance whatever the role played in it, so the exposure was wider
than reported. Writing a publication, be it created or updated, now requires
that role indeed.

KmeliaResourceTest covers the checks. The war had no test at all, hence the
test dependency added to its POM.

Co-Authored-By: Claude Opus 5 &lt;noreply@anthropic.com&gt;
</comment><date>2026-09-28 14:37:34 +0200</date><id>b7db955aa0a1cdeaf903b52ddce739e32d3836fd</id><msg>Fix vulnerability #939</msg><path><editType>edit</editType><file>kmelia/kmelia-war/src/main/java/org/silverpeas/components/kmelia/web/KmeliaResource.java</file></path><path><editType>add</editType><file>kmelia/kmelia-war/src/test/java/org/silverpeas/components/kmelia/web/KmeliaResourceTest.java</file></path><path><editType>edit</editType><file>kmelia/kmelia-war/pom.xml</file></path></item><item _class='hudson.plugins.git.GitChangeSet'><affectedPath>delegatednews/delegatednews-war/src/main/java/org/silverpeas/components/delegatednews/web/ListDelegatedNewsResource.java</affectedPath><affectedPath>delegatednews/delegatednews-war/src/test/java/org/silverpeas/components/delegatednews/web/ListDelegatedNewsResourceTest.java</affectedPath><commitId>ce910d20953d1f7a5129974ec71e8dfabfe1f973</commitId><timestamp>1790599054000</timestamp><author><absoluteUrl>https://integration.silverpeas.org/jenkins/user/mmoquillon</absoluteUrl><fullName>Miguel Moquillon</fullName></author><authorEmail>miguel.moquillon@gmail.com</authorEmail><comment>Reserve the management of the delegated news to the managers

Modifying and deleting the delegated news is reserved to the managers of the
application, as its user interface applies on its side. The REST service was
granted against a mere access to the component instance, whatever the role
played in it, so any of its users was able to reorder and to delete them by
requesting it directly.

Found while auditing the other REST resources against the flaw reported by the
issue #939 of this repository.

ListDelegatedNewsResourceTest covers the check.

Co-Authored-By: Claude Opus 5 &lt;noreply@anthropic.com&gt;
</comment><date>2026-09-28 14:37:34 +0200</date><id>ce910d20953d1f7a5129974ec71e8dfabfe1f973</id><msg>Reserve the management of the delegated news to the managers</msg><path><editType>edit</editType><file>delegatednews/delegatednews-war/src/main/java/org/silverpeas/components/delegatednews/web/ListDelegatedNewsResource.java</file></path><path><editType>add</editType><file>delegatednews/delegatednews-war/src/test/java/org/silverpeas/components/delegatednews/web/ListDelegatedNewsResourceTest.java</file></path></item><item _class='hudson.plugins.git.GitChangeSet'><affectedPath>kmelia/kmelia-war/src/main/java/org/silverpeas/components/kmelia/servlets/AjaxServlet.java</affectedPath><commitId>de9cf8606c9910989890a6d004cd47a8e2f611ca</commitId><timestamp>1790599054000</timestamp><author><absoluteUrl>https://integration.silverpeas.org/jenkins/user/mmoquillon</absoluteUrl><fullName>Miguel Moquillon</fullName></author><authorEmail>miguel.moquillon@gmail.com</authorEmail><comment>Take into account sonarcloud feedback
</comment><date>2026-09-28 14:37:34 +0200</date><id>de9cf8606c9910989890a6d004cd47a8e2f611ca</id><msg>Take into account sonarcloud feedback</msg><path><editType>edit</editType><file>kmelia/kmelia-war/src/main/java/org/silverpeas/components/kmelia/servlets/AjaxServlet.java</file></path></item><kind>git</kind></changeSet><culprit><absoluteUrl>https://integration.silverpeas.org/jenkins/user/mmoquillon</absoluteUrl><fullName>Miguel Moquillon</fullName></culprit><inProgress>false</inProgress><previousBuild><number>570</number><url>https://integration.silverpeas.org/jenkins/job/Silverpeas_Stable_AutoDeploy/570/</url></previousBuild></workflowRun>