Hello everyone,

I've been checking the usage of the commons-fileupload component because 
versions previous to 1.3.1 have a security issue (CVE-2014-0050)

I see it referenced in the following pom.xml files:

/sling/tooling/support/install/pom.xml has version number 1.2.2
/sling/contrib/scripting/script-console/pom.xml has version number 1.1.1
/sling/contrib/extensions/obr/pom.xml has version number 1.1.1
/sling/bundles/commons/log/pom.xml has version number 1.2.1
/sling/bundles/engine/pom.xml has version number 1.3


The usage doesn't seem dangerous, but it would be nice to upgrade the versions 
to 1.3.1 to be sure.

Best regards.
Jose Antonio Insua

Reply via email to