Skip to content

PD-14452 Refactored notification item mapping and post-processing logic into NotificationMapperV2 and NotificationMapperV3, aligning with the existing mapper architectural pattern. - #7756

Merged
amontenegro merged 5 commits into
mainfrom
camelia-orcid/PD-14452
Oct 8, 2026

Conversation

@Camelia-Orcid

Copy link
Copy Markdown
Collaborator

Consolidated item mappings (Item <-> NotificationItemEntity), external identifier mappings, and JSON additionalInfo conversions into NotificationMapperV2 and NotificationMapperV3.
Added @AfterMapping post-processing hooks in NotificationMapperV2 and NotificationMapperV3 to guarantee non-null Items containers and null-safe external identifier instances.
Updated JpaJaxbNotificationAdapterImpl (v2 and v3) to delegate item mapping and notification post-processing to NotificationMapperV2 and NotificationMapperV3 via Spring component injection.
Added unit tests in NotificationMapperV2Test and NotificationMapperV3Test verifying bidirectional item mapping and Items initialization.

…ic into NotificationMapperV2 and NotificationMapperV3, aligning with the existing mapper architectural pattern.

Consolidated item mappings (Item <-> NotificationItemEntity), external identifier mappings, and JSON additionalInfo conversions into NotificationMapperV2 and NotificationMapperV3.
Added @AfterMapping post-processing hooks in NotificationMapperV2 and NotificationMapperV3 to guarantee non-null Items containers and null-safe external identifier instances.
Updated JpaJaxbNotificationAdapterImpl (v2 and v3) to delegate item mapping and notification post-processing to NotificationMapperV2 and NotificationMapperV3 via Spring component injection.
Added comprehensive unit tests in NotificationMapperV2Test and NotificationMapperV3Test verifying bidirectional item mapping and Items initialization.
@Camelia-Orcid

Copy link
Copy Markdown
Collaborator Author

@orcid-sast

orcid-sast Bot commented Oct 8, 2026

Copy link
Copy Markdown

Semgrep found 1 ssc-fedf6bab-e20c-4f00-86a0-12bdb3497926 finding:

🟠 High severity issue identified in your code:

Risk: Affected versions of org.apache.httpcomponents.core5:httpcore5-h2 are vulnerable to Uncontrolled Resource Consumption. The HTTP/2 stream multiplexer initializes its HPACK decoder with the protocol initial SETTINGS_MAX_HEADER_LIST_SIZE of Integer.MAX_VALUE instead of the locally configured limit, so the configured maximum header list size is not enforced until the peer acknowledges the local SETTINGS frame. A remote peer can send an oversized compressed header block during that pre-acknowledgement window to force unbounded memory allocation and cause a denial of service. Both HTTP/2 clients and servers are affected, and the default configuration is vulnerable because the limit it specifies is ignored during that same window.

Fix: Upgrade this library to at least version 5.4.3 at ORCID-Source/orcid-core/maven_dep_tree.txt:69.

Reference(s): https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-41095, GHSA-v3jc-474w-2wm6, CVE-2026-54428

Semgrep found 1 ssc-f7336963-923e-41a8-a6ed-81d763eecbea finding:

🟠 High severity issue identified in your code:

Risk: Affected versions of org.apache.activemq:activemq-all, org.apache.activemq:activemq-broker, and org.apache.activemq:apache-activemq are vulnerable to Improper Input Validation. Apache ActiveMQ fails to fully validate non-parenthesized composite discovery wrappers (e.g. masterslave:vm://...,..., static:vm://...) passed to the broker addNetworkConnector(String) and addConnector(String) operations, bypassing the CVE-2026-34197 fix. A crafted discovery URI can spin up a vm:// transport whose brokerConfig loads a remote Spring XML application context via ResourceXmlApplicationContext, resulting in arbitrary code execution in the broker JVM.

Fix: Upgrade this library to at least version 6.2.6 at ORCID-Source/orcid-core/maven_dep_tree.txt:91.

Reference(s): https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-33576, GHSA-v853-w46p-fv2h, CVE-2026-34197, CVE-2026-45505

Semgrep found 1 ssc-61dca6de-7d56-4a95-a423-eace2f55b54e finding:

🟠 High severity issue identified in your code:

Risk: Affected versions of org.apache.activemq:activemq-all, org.apache.activemq:activemq-broker, and org.apache.activemq:apache-activemq are vulnerable to Improper Input Validation. Apache ActiveMQ Classic exposes the Jolokia JMX-HTTP bridge at /api/jolokia/ with a default access policy that permits exec operations on ActiveMQ MBeans. An authenticated attacker can invoke BrokerService.addNetworkConnector(String) with a crafted discovery URI that abuses the VM transport brokerConfig parameter (via a masterslave:// URL) to load an attacker-controlled Spring XML application context, achieving arbitrary code execution through bean factory methods such as Runtime.exec(). Upgrade to 5.19.7 or 6.2.6.

Fix: Upgrade this library to at least version 6.2.6 at ORCID-Source/orcid-core/maven_dep_tree.txt:91.

Reference(s): https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-33577, GHSA-hg6c-8mvr-jqc9, CVE-2026-42588

Semgrep found 1 ssc-a9fb67db-b7db-4f1c-b697-50b6fc9bde37 finding:

🟠 High severity issue identified in your code:

Risk: Affected versions of org.apache.activemq:activemq-all, org.apache.activemq:activemq-broker, and org.apache.activemq:apache-activemq are vulnerable to Improper Control of Generation of Code ('Code Injection') / Improper Input Validation. An authenticated attacker can bypass the fix in CVE-2026-34197 by adding a connector using an HTTP Discovery transport via BrokerView.addNetworkConnector or BrokerView.addConnector through Jolokia when the activemq-http module is on the classpath. A malicious HTTP endpoint can return a VM transport through the HTTP URI which bypasses the validation added in CVE-2026-34197. The attacker can then use the VM transport's brokerConfig parameter to load a remote Spring XML application context using ResourceXmlApplicationContext. Because Spring instantiates all singleton beans before the BrokerService validates the configuration, arbitrary code execution occurs on the broker's JVM through bean factory methods such as Runtime.exec().

Fix: Upgrade this library to at least version 6.2.5 at ORCID-Source/orcid-core/maven_dep_tree.txt:91.

Reference(s): https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-25410, GHSA-w3w2-mpp5-92gm, CVE-2026-40466

Semgrep found 1 ssc-4a2173e8-253a-468a-8541-9668c7792389 finding:

🟠 High severity issue identified in your code:

Risk: Affected versions of org.apache.activemq:activemq-all, org.apache.activemq:activemq-broker, and org.apache.activemq:apache-activemq are vulnerable to Improper Input Validation. An authenticated attacker can exploit this vulnerability by using the Apache ActiveMQ admin web console to construct a malicious broker name that bypasses name validation to include an xbean binding. The attacker can then use the DestinationView mbean to send a message that triggers a VM transport creation referencing the malicious broker name, causing Spring ResourceXmlApplicationContext to load a remote Spring XML application context. Because Spring instantiates all singleton beans before BrokerService validates the configuration, this leads to arbitrary code execution on the broker JVM through bean factory methods such as Runtime.exec().

Fix: Upgrade this library to at least version 6.2.5 at ORCID-Source/orcid-core/maven_dep_tree.txt:91.

Reference(s): https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-25412, GHSA-mr6m-xj7v-3cv3, CVE-2026-41044

@Camelia-Orcid
Camelia-Orcid marked this pull request as draft October 8, 2026 18:12
@Camelia-Orcid
Camelia-Orcid marked this pull request as ready for review October 8, 2026 18:56
@amontenegro
amontenegro merged commit 25e2bb5 into main Oct 8, 2026
21 checks passed
@amontenegro
amontenegro deleted the camelia-orcid/PD-14452 branch October 8, 2026 19:01
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants