From 43b958cb3a4930d83975a72933991f0f42a1931f Mon Sep 17 00:00:00 2001
From: "copilot-swe-agent[bot]" <198982749+Copilot@users.noreply.github.com>
Date: Mon, 2 Feb 2026 10:47:12 +0000
Subject: [PATCH 1/2] Initial plan
From a4e057da124153c85dde806b4e0a430f696ef291 Mon Sep 17 00:00:00 2001
From: "copilot-swe-agent[bot]" <198982749+Copilot@users.noreply.github.com>
Date: Mon, 2 Feb 2026 10:53:00 +0000
Subject: [PATCH 2/2] Add Rhino 1.7.14 dependency override to fix XXE
vulnerability
Co-authored-by: daniel-kmiecik <97676382+daniel-kmiecik@users.noreply.github.com>
---
pom.xml | 5 +++++
1 file changed, 5 insertions(+)
diff --git a/pom.xml b/pom.xml
index f0107fbef1..ed0d5eba4b 100644
--- a/pom.xml
+++ b/pom.xml
@@ -349,6 +349,11 @@
${wiremock-version}
test
+
+ org.mozilla
+ rhino
+ 1.7.14
+