Uploaded image for project: 'UIMA'
  1. UIMA
  2. UIMA-6486

Fix for FileUtil vulnerability in UIMA 2.*?

    XMLWordPrintableJSON

Details

    • Bug
    • Status: Resolved
    • Major
    • Resolution: Abandoned
    • 2.11.0SDK
    • None
    • None
    • None

    Description

      Hi, 

      we distribute a custom annotator built on UIMA v2, which is affected by https://nvd.nist.gov/vuln/detail/CVE-2022-32287. We do not have any near-term bandwidth to upgrade our library to v3, and more critically some of our customers have other pipelines still running on v2 that they may not be able to migrate to v3 any time soon.

      Are there any plans to deliver a new v2.11 bugfix release that addresses this vulnerability?

      Thanks!

      Attachments

        Activity

          People

            rec Richard Eckart de Castilho
            bdeboe Benjamin De Boe
            Votes:
            0 Vote for this issue
            Watchers:
            2 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: