Meta tags:
Headings (most frequently used words):
apache, velocity, foundation, general, releases, development, community, developer, resources, archive, what, is, the, project, recent, news, software, projects, release, status, security, model, more, information, templates, loading, context,
Text of the page (most frequently used words):
the (48), velocity (41), #apache (28), and (18), engine (14), web (14), project (13), #software (12), for (11), foundation (8), template (7), are (6), that (6), tools (6), source (6), can (6), code (6), more (5), how (5), this (5), release (5), java (5), license (4), with (4), class (4), context (4), configuration (4), all (4), from (4), model (4), available (4), projects (4), development (4), version (3), distribution (3), page (3), information (3), about (3), see (3), provides (3), ensure (3), not (3), dangerous (3), its (3), cannot (3), application (3), defined (3), templates (3), you (3), work (3), open (3), news (3), used (3), site (3), asf (3), 2020 (2), under (2), contact (2), find (2), get (2), involved (2), who (2), works (2), which (2), does (2), authors (2), properties (2), already (2), powerful (2), security (2), currently (2), none (2), dash (2), other (2), standalone (2), here (2), community (2), based (2), process (2), 2024 (2), released (2), reports (2), view (2), according (2), mvc (2), designers (2), programmers (2), focus (2), solely (2), pages (2), developer (2), copyright, licensed, feather, logo, trademarks, faq, home, out, people, behind, secureuberspector, helper, helps, contain, any, user, facing, editing, scenario, but, just, provided, know, advance, populated, possibly, ban, potentially, classes, responsibility, audit, every, object, placed, accessible, starting, point, rely, loaders, file, webapp, descriptor, container, those, configurations, compromised, come, malicious, vulnerability, attacker, control, files, they, have, far, attack, vectors, than, injection, loading, combined, binary, tar, zip, formats, downloaded, our, download, alpha, beta, status, contains, useful, infrastructure, build, non, using, will, integration, velocityviewservlet, struts, actual, templating, came, because, heard, somewhere, probably, right, place, start, offers, following, support, characterized, collaborative, consensus, pragmatic, desire, create, high, quality, leads, way, field, 2021, advisory, sandbox, bypass, cve, 13936, recent, charged, creation, maintenance, related, created, free, charge, public, capabilities, reach, well, beyond, realm, example, generate, sql, postscript, xml, either, utility, generating, integrated, component, systems, instance, services, enabling, them, facilitating, applications, true, various, frameworks, when, parallel, develop, sites, controller, meaning, creating, looks, good, writing, top, notch, separates, making, maintainable, over, lifespan, providing, viable, alternative, jsps, php, server, permits, anyone, use, simple, yet, language, reference, objects, what, thanks, sponsorship, repository, infos, website, docbook, dvsl, texen, anakia, archive, building, guidelines, coding, standards, issues, resources, board, wiki, releases, downloads, welcome, general, http, org,
Text of the page (random words):
the apache velocity project the apache velocity project http velocity apache org apache velocity general welcome news downloads releases engine 2 4 1 tools 3 1 development engine tools community who we are contact us get involved wiki how it works board reports developer resources issues coding standards project guidelines site building release process archive anakia 1 0 texen 1 0 dvsl 1 0 docbook fx 1 0 apache foundation apache website how the asf work asf developer infos asf source code repository sponsorship thanks what is velocity velocity is a java based template engine it permits anyone to use a simple yet powerful template language to reference objects defined in java code when velocity is used for web development web designers can work in parallel with java programmers to develop web sites according to the model view controller mvc model meaning that web page designers can focus solely on creating a site that looks good and programmers can focus solely on writing top notch code velocity separates java code from the web pages making the web site more maintainable over its lifespan and providing a viable alternative to java server pages jsps or php velocity s capabilities reach well beyond the realm of the web for example it can be used to generate sql postscript and xml from templates it can be used either as a standalone utility for generating source code and reports or as an integrated component of other systems for instance velocity provides template services for various web frameworks enabling them with a view engine facilitating development of web applications according to a true mvc model the apache velocity project velocity is a project of the apache software foundation charged with the creation and maintenance of open source software related to the apache velocity engine all software created at the velocity project is available under the apache software license and free of charge for the public recent news 2024 10 14 velocity engine 2 4 1 released 2024 09 07 velocity engine 2 4 released 2021 03 09 security advisory for velocity engine velocity sandbox bypass cve 2020 13936 see all news apache software foundation the apache software foundation provides support for the apache community of open source software projects the apache projects are characterized by a collaborative consensus based development process an open and pragmatic software license and a desire to create high quality software that leads the way in its field apache velocity projects apache velocity offers the following projects velocity engine dash this is the actual templating engine which does all the work if you came here because you heard about velocity somewhere on the web this is probably the right place to start velocity tools dash this project contains tools and other useful infrastructure to build web and non web application using the velocity engine you will find e g code for struts integration or the standalone velocityviewservlet here release status project release version alpha beta rc release version velocity engine 2 4 1 currently none available velocity tools 3 1 currently none available the release distribution is available as a combined source binary distribution in tar gz and zip formats and can be downloaded from our download page security model templates loading velocity engine and velocity tools rely on the template loaders defined in the velocity properties configuration file and or properties defined in the webapp descriptor or web container configuration if those configurations are compromised velocity cannot ensure that templates do not come from a malicious source this is not a velocity vulnerability if the attacker is already in control of the web application configuration files they already have far more powerful attack vectors than template injection velocity context velocity engine provides a secureuberspector helper class which helps ensure that the velocity context does not contain any dangerous class in a user facing template editing scenario but this class and its configuration are just provided as a starting point velocity cannot know in advance how the velocity context is populated and cannot possibly ban all potentially dangerous classes it is the responsibility of the application authors to audit every object placed in the context to ensure that no dangerous class is accessible to template authors more information for more information about the apache velocity project see how the apache velocity project works who are the people behind the apache velocity project find out how to get involved with the apache velocity project contact the apache velocity project for more information about the apache software foundation see foundation home page apache license and distribution faq copyright 2020 the apache software foundation licensed under the apache license version 2 0 apache and the apache feather logo are trademarks of the apache software foundation
|