-
Notifications
You must be signed in to change notification settings - Fork 129
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
CVE-2019-12415 #85
Comments
Thanks for this, if you would submit a PR for upgrading to the latest POI version it would be great. Also, if you could add lein-nvd to the project.clj it would be great, even more so if you also add it to the Travis CI. |
Hi! Thanks for the response. Happy to see #81 merged. Currently I cannot offer OSS contributions due to IP concerns. |
No worries. Thank you for taking time to report the issue and mentioning the to me unknown |
What is the status of this issue & PR? |
I verified just now and checked that upgrading to I'd suggest creating that thinner PR. In the meantime, if feeling adventurous I think you can just bump |
Here it is: #94 |
Can someone please merge the PR? |
Anyone? |
Closing this as fixed. Docjure version 1.18.0 uses the much newer POI version 5.2.2. |
Hi there,
using
[dk.ative/docjure "1.12.0"]
will bring in CVE-2019-12415, as lein-nvd would indicate.That is fixed with
[org.apache.poi/poi "4.1.1"]
, but one cannot pull that change without incurring into #82, so #81 would be a great start.cc/ @manuelherzog
The text was updated successfully, but these errors were encountered: