Re: [dspace-tech] Apache Commons Text vulnerability

2022-10-20 Thread Mark H. Wood
On Thu, Oct 20, 2022 at 01:51:26AM -0700, oriol@udl.cat wrote: > There has been discovered a vulnerability affecting versions 1.5 to 1.9 of > Apache Commons Text: > https://nvd.nist.gov/vuln/detail/CVE-2022-42889 > > I've seen DSpace 7 uses the 1.9 version of this library: >

[dspace-tech] Apache Commons Text vulnerability

2022-10-20 Thread oriol....@udl.cat
Hi all, There has been discovered a vulnerability affecting versions 1.5 to 1.9 of Apache Commons Text: https://nvd.nist.gov/vuln/detail/CVE-2022-42889 I've seen DSpace 7 uses the 1.9 version of this library: https://github.com/DSpace/DSpace/blob/main/dspace-api/pom.xml#L850 It is recommended