DEV Community

Query Filter
Query Filter

Posted on

gradle-161

This document details the build version analysis, Java 21 runtime behavior, Spring Framework 7.0 / Jakarta EE compatibility, introspection vulnerabilities, and recommended configuration for Apache Velocity Engine 1.7 (org.apache.velocity:velocity:1.7).


Artifact: org.apache.velocity:velocity:1.7

Original JDK Target & Baseline Requirements

  • Artifact Name: org.apache.velocity:velocity:1.7 (Legacy artifact coordinates)
  • Compile-Time JDK Baseline: Java 5 (Major Version 49.0) / Java 6 (Major Version 50.0).
  • Java 21 Compatibility Status: Incompatible / High Risk.
    • Runtime Introspection Failures: Legacy introspection engine (ClassMap / Introspector) attempts reflective access on package-private and protected methods of Java internal classes (e.g., standard collections, map implementations). On Java 17 and Java 21, JPMS strong encapsulation throws InaccessibleObjectException during VTL property resolution.
    • Critical Security Vulnerabilities: Retains multiple unpatched Remote Code Execution (RCE) and template injection vulnerabilities (e.g., CVE-2020-13936).
    • Namespace & Dependency Conflicts: Relies on dead, EOL dependencies (commons-collections:commons-collections:3.2.1, commons-lang:commons-lang:2.4).

Key Architectural & Technical Characteristics on Java 21

  1. Strong Encapsulation & Introspection Breakage (JPMS):

    • Velocity 1.7 uses deep reflection to evaluate VTL property accesses (e.g., $foo.bar, $list.size()).
    • When Velocity reflects across encapsulation boundaries—such as accessing non-public methods or internal implementations of standard JDK classes (java.util.*, java.lang.*)—Java 21 strictly denies access and throws java.lang.reflect.InaccessibleObjectException.
  2. Spring 7.0 & Jakarta EE 11 Compatibility Blockers:

    • Spring Integration Removed: Spring Framework removed legacy Velocity support classes (VelocityEngineFactoryBean, VelocityConfigurer) starting with Spring Framework 5.0. Modern Spring versions do not support Velocity 1.7 natively.
    • Servlet API Misalignment: Optional web engine components in velocity-tools for 1.7 rely on javax.servlet.* interfaces, which are incompatible with Spring 7.0 / Jakarta EE 11 (jakarta.servlet.*).
  3. Obsolete Transitive Dependencies:

    • Transitively pulls in commons-collections 3.2.1 and commons-lang 2.4.
    • These outdated libraries pollute the classpath and interfere with modern Java 21 dependency management.

JVM Command-Line Flag Options (Temporary Workaround Only)

If forced to run velocity:1.7 on Java 21 during interim migration phases, reflective errors require opening JDK internal packages:

--add-opens java.base/java.lang=ALL-UNNAMED
--add-opens java.base/java.util=ALL-UNNAMED
Enter fullscreen mode Exit fullscreen mode

Recommended Build Configuration & Migration Strategy

Action Required: Upgrade to Velocity Engine 2.3+ or 2.4

Migrate to the active Apache Velocity Engine artifact path under org.apache.velocity:velocity-engine-core.

Maven Configuration

<!-- REMOVE Legacy Velocity 1.7 Dependency -->
<!--
<dependency>
    <groupId>org.apache.velocity</groupId>
    <artifactId>velocity</artifactId>
    <version>1.7</version>
</dependency>
-->

<!-- ADD Modern Velocity Engine Core -->
<dependency>
    <groupId>org.apache.velocity</groupId>
    <artifactId>velocity-engine-core</artifactId>
    <version>2.4</version>
</dependency>
Enter fullscreen mode Exit fullscreen mode

Gradle Configuration

// REMOVE Legacy
// implementation 'org.apache.velocity:velocity:1.7'

// ADD Modern Velocity Engine
implementation 'org.apache.velocity:velocity-engine-core:2.4'
Enter fullscreen mode Exit fullscreen mode

Backward Compatibility Configuration (Velocity 2.x)

To retain Velocity 1.7 syntax and rendering behaviors when upgrading to Velocity Engine 2.x, configure the following runtime properties in velocity.properties:

# Enable Velocity 1.x Backward Compatibility Mode
runtime.conversion.handler = none
space.gobbling = bc
directive.if.emptycheck = false
velocimacro.preserve.arguments.literals = true
Enter fullscreen mode Exit fullscreen mode

Summary Checklist for Java 21 Migration

Requirement / Check Status Notes
Java 21 Bytecode Compatible? NO Fails with InaccessibleObjectException during VTL reflection without --add-opens.
Spring Framework 7.0 Compatible? NO Support classes removed from Spring 5.0+; requires standalone configuration or Velocity 2.4.
Jakarta EE Collision? YES Web components rely on javax.servlet.*.
Target Upgrade Artifact org.apache.velocity:velocity-engine-core:2.4 Modern, actively maintained drop-in replacement with compatibility flags.
Security Risk Level CRITICAL Multiple unpatched RCE / template injection CVEs present in 1.7.

Top comments (0)