Skip to content

transitive dependency to commons io with CVE-2024-47554 #223

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Open
ChrWeissDe opened this issue May 6, 2025 · 0 comments
Open

transitive dependency to commons io with CVE-2024-47554 #223

ChrWeissDe opened this issue May 6, 2025 · 0 comments

Comments

@ChrWeissDe
Copy link

ChrWeissDe commented May 6, 2025

We recognized that the plugin is using under the cover commons-io package with the version 2.11.
Unfortunately this version has got a CVE --> CVE-2024-47554.
(see also: https://lists.apache.org/thread/6ozr91rr9cj5lm0zyhv30bsp317hk5z1)

Thus an update of the plugin with an updated commons io version would be great.
Is there any update / new version planned?

Thanks!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant