You are viewing a plain text version of this content. The canonical link for it is here.
Posted to notifications@james.apache.org by GitBox <gi...@apache.org> on 2021/08/20 13:01:37 UTC

[GitHub] [james-project] chibenwa opened a new pull request #609: [UPGRADE] JSOUP 1.14.1 -> 1.14.2 to address CVE-2021-37714

chibenwa opened a new pull request #609:
URL: https://github.com/apache/james-project/pull/609


   https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-37714
   
   jsoup is a Java library for working with HTML. Those using jsoup versions
   prior to 1.14.2 to parse untrusted HTML or XML may be vulnerable to DOS
   attacks. If the parser is run on user supplied input, an attacker may supply
   content that causes the parser to get stuck (loop indefinitely until
   cancelled), to complete more slowly than usual, or to throw an unexpected
   exception. This effect may support a denial of service attack. The issue is
   patched in version 1.14.2. There are a few available workarounds. Users may
   rate limit input parsing, limit the size of inputs based on system resources,
   and/or implement thread watchdogs to cap and timeout parse runtimes.


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: notifications-unsubscribe@james.apache.org

For queries about this service, please contact Infrastructure at:
users@infra.apache.org



---------------------------------------------------------------------
To unsubscribe, e-mail: notifications-unsubscribe@james.apache.org
For additional commands, e-mail: notifications-help@james.apache.org


[GitHub] [james-project] chibenwa merged pull request #609: [UPGRADE] JSOUP 1.14.1 -> 1.14.2 to address CVE-2021-37714

Posted by GitBox <gi...@apache.org>.
chibenwa merged pull request #609:
URL: https://github.com/apache/james-project/pull/609


   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: notifications-unsubscribe@james.apache.org

For queries about this service, please contact Infrastructure at:
users@infra.apache.org



---------------------------------------------------------------------
To unsubscribe, e-mail: notifications-unsubscribe@james.apache.org
For additional commands, e-mail: notifications-help@james.apache.org