URGENT: Mining-script in Primfaces-Page? Where does it come from??

UI Components for JSF
kukeltje
Expert Member
Posts: 9605
Joined: 17 Jun 2010, 13:34
Location: Netherlands

31 Jan 2018, 18:31

You can upgrade... Always good to keep up-to-date with small steps... And you can also check the differences in code and create a patch yourself... The code IS open and freely accessible... So saying you are 'ransomed' is too bold of a statement. (and no, I won't get rich of this, I do all support in my free time)

eodom
Posts: 3
Joined: 30 Jan 2018, 12:57

01 Feb 2018, 11:10

It is just my point of view.
We have an app created with maven and primefaces from a third party. Anybody left from this period in the team.
No skills left.
Since a couple of days, this app is compromised with a security issue, as a thousand of websites (Google search).
I am looking for help, and the only choice I got is To pay or To fix it by myself. Well... Not really a good start.
I am not looking for addon, extras. Just fix this issue.
I am ok with subscription. But why there is a communitary version without security fixes ?
Do I ask to maven team to get the fix ?

kukeltje
Expert Member
Posts: 9605
Joined: 17 Jun 2010, 13:34
Location: Netherlands

01 Feb 2018, 15:31

eodom wrote:
01 Feb 2018, 11:10
We have an app created with maven and primefaces from a third party. Anybody left from this period in the team.
No skills left.
I understand, but that does not mean you are ransomed by PrimeFaces... You could state the same for your organization.
eodom wrote:
01 Feb 2018, 11:10
I am looking for help, and the only choice I got is To pay or To fix it by myself. Well... Not really a good start.
No, you could also upgrade to 6.1 (the fact that upgrades were not done is also something that was decided by your organisation and cannot be blamed on PrimeFaces
eodom wrote:
01 Feb 2018, 11:10
I am not looking for addon, extras. Just fix this issue.
I understand, that is why I stated you yould 'backport' the fix from the 6.1 code to the 5.3 code.
eodom wrote:
01 Feb 2018, 11:10
I am ok with subscription. But why there is a communitary version without security fixes ?
There is also a community version WITH the fix... 6.1
eodom wrote:
01 Feb 2018, 11:10
Do I ask to maven team to get the fix ?
The 'maven team'???
Last edited by kukeltje on 19 Feb 2018, 15:48, edited 1 time in total.

prancius
Posts: 21
Joined: 27 Aug 2010, 12:50

19 Feb 2018, 13:30

Any solutions?

tandraschko
PrimeFaces Core Developer
Posts: 3979
Joined: 03 Dec 2010, 14:11
Location: Bavaria, DE
Contact:

19 Feb 2018, 14:16

Thomas Andraschko

PrimeFaces | PrimeFaces Extensions

Apache Member | OpenWebBeans, DeltaSpike, MyFaces, BVal, TomEE

Sponsor me: https://github.com/sponsors/tandraschko
Blog: http://tandraschko.blogspot.de/
Twitter: https://twitter.com/TAndraschko

Post Reply

Return to “PrimeFaces”

  • Information
  • Who is online

    Users browsing this forum: No registered users and 36 guests