Uploaded image for project: 'Maven'
  1. Maven
  2. MNG-7507

Upgrade commons io to 2.7

    XMLWordPrintableJSON

Details

    • Dependency upgrade
    • Status: Closed
    • Major
    • Resolution: Won't Fix
    • 3.8.6
    • None
    • Dependencies
    • None

    Description

       Maven 3.8.6 distributes ./apache-maven-3.8.6/lib/commons-io-2.6.jar. This jar is vulnerable to CVE-2021-29425.

      Are there plans to upgrade to commons io 2.7 in the next version of maven ?

      Attachments

        Activity

          People

            Unassigned Unassigned
            PeterHBower Peter Bower
            Votes:
            0 Vote for this issue
            Watchers:
            2 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: