[
https://issues.apache.org/jira/browse/FREEMARKER-190?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17411139#comment-17411139
]
PowerCOM_STARWAR edited comment on FREEMARKER-190 at 9/7/21, 11:44 AM:
-----------------------------------------------------------------------
1.but it is unsafe, the higher version of dom4j is comcaptible with old one. i
think we should foucs on the security.
2.and it is default depend jars in the ivy.xml, not optional:
*<dependency org="dom4j" name="dom4j" rev="1.3" conf="build.base->default" />
<!-- legacy -->*
was (Author: powercom_starwar):
but it is unsafe, the higher version of dom4j is comcaptible with old one. i
think we should foucs on the security.
> The jar dom4j has known security issue that Freemarker compiles dependend on
> it
> --------------------------------------------------------------------------------
>
> Key: FREEMARKER-190
> URL: https://issues.apache.org/jira/browse/FREEMARKER-190
> Project: Apache Freemarker
> Issue Type: Wish
> Components: engine
> Affects Versions: 2.3.31
> Reporter: PowerCOM_STARWAR
> Priority: Major
>
> Hi, friend. When i compile the Freemarker, i find it depends on the jar dom4j
> ,and its version is 1.3. From the Internet, this version 1.3 of dom4j has
> security issues, so please upgrade to the safety version.Thanks.
> The security issue number CVE-2020-10683 and link:
> [https://nvd.nist.gov/vuln/detail/CVE-2020-10683]
> The Security issue number CVE-2018-1000632 and link:
> [https://nvd.nist.gov/vuln/detail/CVE-2018-1000632.]
>
>
--
This message was sent by Atlassian Jira
(v8.3.4#803005)