Announcement: JBossWS 7.4.1.Final is released!
JBossWS-CXF 7.4.1.Final has been released. In this release we upgraded Apache CXF to 4.1.8, which includes a
security improvement that blocks decoupled WS-Addressing destinations by default as a hardening measure against
SSRF attacks. JBossWS-CXF enables decoupled WS-Addressing destinations by default to preserve backward
compatibility, while allowing users to opt out and leverage the new Apache CXF security behaviour via the
org.jboss.ws.cxf.decoupledEndpointEnabled property.
This release also marks the point where the 7.4.x maintenance branch will be created in the jbossws-cxf repository,
as development moves on to the next major release. See the GitHub discussion for more details.
See more details in the last Blog post
Please try out this release, and let us know if you have any issues or questions.
JBossWS is a framework that supplies Eclipse Enterprise for Java (EE4J) compliant Web Service technologies to WildFly and JBoss Enterprise Application Platform (JBoss EAP). JBossWS is built upon the Web Services components of Apache CXF. JBossWS is a Commonhaus Foundation project.
Features
JBossWS provides a set of features, options and tools that make it easy to build, manage and monitor web services. It provides endpoint metrics, record management, endpoint address rewrite support and the like. By its integration with CXF, JBossWS supports the Web Services Standards for SAAJ, SOAP, the WS-I Basic Profile, WSDL, WS-Addressing, WS-Policy, WS-ReliableMessaging, WS-Security, WS-SecurityPolicy, WS-SecureConverstation, and WS-Trust (partial).