[io] Regarding CVE-2021-29425: APACHE COMMONS IO UPDATE

2021-12-13 Thread Surendra Pulukuri
Hi Team, As per this security vulnerability CVE-2021-29425, we are using commons-io v2.4 as a 3rd party application in our code base (Java1.7 compatible), to move to latest version of commons-io where the security vulnerability CVE-2021-29425 has fixed starting from v2.7 OR v2.11.0 both are

Re: [io] Regarding CVE-2021-29425: APACHE COMMONS IO UPDATE

2021-12-13 Thread Gary Gregory
Hello Surendra, You will need to update to Commons IO 2.7 or later, the current version is 2.11.0. Commons IO 2.4 is based on Java 6, see https://commons.apache.org/proper/commons-io/ for which version requires which Java version. There is no currently planned support for old versions of