Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

CVE-2019-12415 #85

Closed
vemv opened this issue Oct 30, 2019 · 9 comments
Closed

CVE-2019-12415 #85

vemv opened this issue Oct 30, 2019 · 9 comments

Comments

@vemv
Copy link

vemv commented Oct 30, 2019

Hi there,

using [dk.ative/docjure "1.12.0"] will bring in CVE-2019-12415, as lein-nvd would indicate.

That is fixed with [org.apache.poi/poi "4.1.1"], but one cannot pull that change without incurring into #82, so #81 would be a great start.

cc/ @manuelherzog

@mjul
Copy link
Owner

mjul commented Jun 26, 2020

Thanks for this, if you would submit a PR for upgrading to the latest POI version it would be great.
Don't forget to add your name to the list of contributors in the README.md

Also, if you could add lein-nvd to the project.clj it would be great, even more so if you also add it to the Travis CI.

@vemv
Copy link
Author

vemv commented Jun 26, 2020

Hi! Thanks for the response. Happy to see #81 merged.

Currently I cannot offer OSS contributions due to IP concerns.

@mjul
Copy link
Owner

mjul commented Jun 26, 2020

No worries. Thank you for taking time to report the issue and mentioning the to me unknown lein nvd check.

@mjul mjul linked a pull request Jun 26, 2020 that will close this issue
@Jarzka
Copy link
Contributor

Jarzka commented Mar 16, 2021

What is the status of this issue & PR?

@vemv
Copy link
Author

vemv commented Mar 16, 2021

I verified just now and checked that upgrading to [org.apache.poi/poi "4.1.1"] would not break the test suite. #86 was left open because it touches more aspects.

I'd suggest creating that thinner PR.

In the meantime, if feeling adventurous I think you can just bump poi from the given consumer project!

@Jarzka
Copy link
Contributor

Jarzka commented Mar 16, 2021

Here it is: #94

@Jarzka
Copy link
Contributor

Jarzka commented Mar 30, 2021

Can someone please merge the PR?

@Jarzka
Copy link
Contributor

Jarzka commented Apr 22, 2021

Anyone?

@mjul
Copy link
Owner

mjul commented Aug 19, 2022

Closing this as fixed. Docjure version 1.18.0 uses the much newer POI version 5.2.2.

@mjul mjul closed this as completed Aug 19, 2022
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging a pull request may close this issue.

3 participants