Details
-
Task
-
Status: Resolved
-
Minor
-
Resolution: Fixed
-
2.5
-
None
-
None
Description
fop has a dependency on ant 1.8.2, e.g. in
https://svn.apache.org/repos/asf/xmlgraphics/fop/trunk/fop-core/pom.xml
<dependency>
<groupId>org.apache.ant</groupId>
<artifactId>ant</artifactId>
<version>1.8.2</version>
</dependency>
however that version is flagged with vulnerability CVE-2020-1945 by dependency-check-maven.