[
https://issues.apache.org/jira/browse/JCR-3871?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
]
Marcel Reutegger resolved JCR-3871.
-----------------------------------
Resolution: Fixed
Fix Version/s: 2.10.1
Updated the Tika dependency to 1.7, which includes / depends on Apache POI 3.11.
Fixed in trunk: http://svn.apache.org/r1674859
> POI Vulnerabilities
> -------------------
>
> Key: JCR-3871
> URL: https://issues.apache.org/jira/browse/JCR-3871
> Project: Jackrabbit Content Repository
> Issue Type: Bug
> Affects Versions: 2.10
> Reporter: Peter Walsh
> Assignee: Marcel Reutegger
> Fix For: 2.10.1
>
>
> Multiple security vulnerabilities in Apache POI require upgrade to at least
> 3.10.1 or later.
> http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3574
> http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3529
--
This message was sent by Atlassian JIRA
(v6.3.4#6332)