[ https://issues.apache.org/jira/browse/OFBIZ-13265?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ]
Jacques Le Roux closed OFBIZ-13265. ----------------------------------- Fix Version/s: (was: 24.09.02) Resolution: Invalid [commons-fileupload2-jakarta|https://mvnrepository.com/artifact/org.apache.commons/commons-fileupload2-jakarta] and [commons-fileupload2|https://mvnrepository.com/artifact/org.apache.commons/commons-fileupload2] are 2 different things, commons-fileupload2-jakarta is not concerned by this [CVE|https://nvd.nist.gov/vuln/detail/CVE-2025-48976] > Update Apache commons-fileupload to last version (CVE-2025-48976) > ----------------------------------------------------------------- > > Key: OFBIZ-13265 > URL: https://issues.apache.org/jira/browse/OFBIZ-13265 > Project: OFBiz > Issue Type: Bug > Components: content, framework > Affects Versions: 24.09.01 > Reporter: Jacques Le Roux > Assignee: Jacques Le Roux > Priority: Major > > https://lists.apache.org/thread/mqbtql9d0gzmxmdvoj0r6yqj51bofp6m > So this is an update to Apache Commons FileUpload 2.0.0-M4 -- This message was sent by Atlassian Jira (v8.20.10#820010)