Skip to content

[Enhancement]: Bump vulnerable commons-compress version #9875

@jphelpsqred

Description

@jphelpsqred

Module

Core

Proposal

org.apache.commons:commons-compress:1.24 (all versions >= 1.3, < 1.26.0) has a 'high severity' denial of service vulnerability (CVE-2024-25710 )
and needs to be updated to >= 1.26 .

1.27.1 is the latest at this time.

api 'org.apache.commons:commons-compress:1.24.0'

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions