This document details the build version analysis, Java 21 runtime behavior, Spring Framework 7.0 / Jakarta EE compatibility, introspection vulnerabilities, and recommended configuration for Apache Velocity Engine 1.7 (org.apache.velocity:velocity:1.7).
Artifact: org.apache.velocity:velocity:1.7
Original JDK Target & Baseline Requirements
-
Artifact Name:
org.apache.velocity:velocity:1.7(Legacy artifact coordinates) -
Compile-Time JDK Baseline: Java 5 (Major Version
49.0) / Java 6 (Major Version50.0). -
Java 21 Compatibility Status: Incompatible / High Risk.
-
Runtime Introspection Failures: Legacy introspection engine (
ClassMap/Introspector) attempts reflective access on package-private and protected methods of Java internal classes (e.g., standard collections, map implementations). On Java 17 and Java 21, JPMS strong encapsulation throwsInaccessibleObjectExceptionduring VTL property resolution. - Critical Security Vulnerabilities: Retains multiple unpatched Remote Code Execution (RCE) and template injection vulnerabilities (e.g., CVE-2020-13936).
-
Namespace & Dependency Conflicts: Relies on dead, EOL dependencies (
commons-collections:commons-collections:3.2.1,commons-lang:commons-lang:2.4).
-
Runtime Introspection Failures: Legacy introspection engine (
Key Architectural & Technical Characteristics on Java 21
-
Strong Encapsulation & Introspection Breakage (JPMS):
- Velocity 1.7 uses deep reflection to evaluate VTL property accesses (e.g.,
$foo.bar,$list.size()). - When Velocity reflects across encapsulation boundaries—such as accessing non-public methods or internal implementations of standard JDK classes (
java.util.*,java.lang.*)—Java 21 strictly denies access and throwsjava.lang.reflect.InaccessibleObjectException.
- Velocity 1.7 uses deep reflection to evaluate VTL property accesses (e.g.,
-
Spring 7.0 & Jakarta EE 11 Compatibility Blockers:
-
Spring Integration Removed: Spring Framework removed legacy Velocity support classes (
VelocityEngineFactoryBean,VelocityConfigurer) starting with Spring Framework 5.0. Modern Spring versions do not support Velocity 1.7 natively. -
Servlet API Misalignment: Optional web engine components in
velocity-toolsfor 1.7 rely onjavax.servlet.*interfaces, which are incompatible with Spring 7.0 / Jakarta EE 11 (jakarta.servlet.*).
-
Spring Integration Removed: Spring Framework removed legacy Velocity support classes (
-
Obsolete Transitive Dependencies:
- Transitively pulls in
commons-collections 3.2.1andcommons-lang 2.4. - These outdated libraries pollute the classpath and interfere with modern Java 21 dependency management.
- Transitively pulls in
JVM Command-Line Flag Options (Temporary Workaround Only)
If forced to run velocity:1.7 on Java 21 during interim migration phases, reflective errors require opening JDK internal packages:
--add-opens java.base/java.lang=ALL-UNNAMED
--add-opens java.base/java.util=ALL-UNNAMED
Recommended Build Configuration & Migration Strategy
Action Required: Upgrade to Velocity Engine 2.3+ or 2.4
Migrate to the active Apache Velocity Engine artifact path under org.apache.velocity:velocity-engine-core.
Maven Configuration
<!-- REMOVE Legacy Velocity 1.7 Dependency -->
<!--
<dependency>
<groupId>org.apache.velocity</groupId>
<artifactId>velocity</artifactId>
<version>1.7</version>
</dependency>
-->
<!-- ADD Modern Velocity Engine Core -->
<dependency>
<groupId>org.apache.velocity</groupId>
<artifactId>velocity-engine-core</artifactId>
<version>2.4</version>
</dependency>
Gradle Configuration
// REMOVE Legacy
// implementation 'org.apache.velocity:velocity:1.7'
// ADD Modern Velocity Engine
implementation 'org.apache.velocity:velocity-engine-core:2.4'
Backward Compatibility Configuration (Velocity 2.x)
To retain Velocity 1.7 syntax and rendering behaviors when upgrading to Velocity Engine 2.x, configure the following runtime properties in velocity.properties:
# Enable Velocity 1.x Backward Compatibility Mode
runtime.conversion.handler = none
space.gobbling = bc
directive.if.emptycheck = false
velocimacro.preserve.arguments.literals = true
Summary Checklist for Java 21 Migration
| Requirement / Check | Status | Notes |
|---|---|---|
| Java 21 Bytecode Compatible? | NO | Fails with InaccessibleObjectException during VTL reflection without --add-opens. |
| Spring Framework 7.0 Compatible? | NO | Support classes removed from Spring 5.0+; requires standalone configuration or Velocity 2.4. |
| Jakarta EE Collision? | YES | Web components rely on javax.servlet.*. |
| Target Upgrade Artifact | org.apache.velocity:velocity-engine-core:2.4 |
Modern, actively maintained drop-in replacement with compatibility flags. |
| Security Risk Level | CRITICAL | Multiple unpatched RCE / template injection CVEs present in 1.7. |
Top comments (0)