Uploaded image for project: 'Calcite'
  1. Calcite
  2. CALCITE-5025

Upgrade commons-io version from 2.4 to 2.11.0

    XMLWordPrintableJSON

Details

    • Bug
    • Status: Closed
    • Major
    • Resolution: Fixed
    • None
    • 1.30.0
    • None

    Description

      Calcite depends commons-io:commons-io 2.4 – which was released on 2012-06-12 – which can be exploited to access parent directories. In recent months, there have been a fair number of releases for this package and Synk lists this as the only vulnerability it has seen.

      Task is simple, bump the version to 2.7 or higher – if I may suggest just going to 2.11.0.

      Attachments

        Issue Links

          Activity

            People

              ScottReynolds Scott Reynolds
              ScottReynolds Scott Reynolds
              Votes:
              0 Vote for this issue
              Watchers:
              5 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved:

                Time Tracking

                  Estimated:
                  Original Estimate - Not Specified
                  Not Specified
                  Remaining:
                  Remaining Estimate - 0h
                  0h
                  Logged:
                  Time Spent - 20m
                  20m