You are viewing a plain text version of this content. The canonical link for it is here.
Posted to issues@commons.apache.org by "Gary D. Gregory (Jira)" <ji...@apache.org> on 2023/07/09 20:34:00 UTC

[jira] [Closed] (FILEUPLOAD-347) CVE in commons-io versions less than 2.7

     [ https://issues.apache.org/jira/browse/FILEUPLOAD-347?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ]

Gary D. Gregory closed FILEUPLOAD-347.
--------------------------------------
    Fix Version/s: 1.5
       Resolution: Fixed

> CVE in commons-io versions less than 2.7 
> -----------------------------------------
>
>                 Key: FILEUPLOAD-347
>                 URL: https://issues.apache.org/jira/browse/FILEUPLOAD-347
>             Project: Commons FileUpload
>          Issue Type: Task
>    Affects Versions: 1.4
>         Environment: java 17 on macos
>            Reporter: Michael Brewer
>            Priority: Major
>             Fix For: 1.5
>
>         Attachments: Screen Shot 2022-07-17 at 10.19.06 AM.png
>
>
> Current version of commons-fileupload depends on common-io 2.2 which has a medium level CVE. Looks like the github unreleased version is already using the latest, so once this is released the CVE should go away.



--
This message was sent by Atlassian Jira
(v8.20.10#820010)