Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Batik-css-1.8 has high severity vulnerability #13

Closed
tw-mcummings opened this issue Aug 8, 2017 · 4 comments
Closed

Batik-css-1.8 has high severity vulnerability #13

tw-mcummings opened this issue Aug 8, 2017 · 4 comments

Comments

@tw-mcummings
Copy link
Contributor

Hello,

Using antisamy causes batik-css-1.8.jar to be include as a run-time dependency. There is a high severity CVE against this library: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-5662.

batik-1.9 was recently release which fixes this issue. Any chance we could get a new version of antisamy with this instead of 1.8? I could do a pull request if you like.

Thanks!

@nahsra
Copy link
Owner

nahsra commented Aug 8, 2017 via email

@tw-mcummings
Copy link
Contributor Author

Hello nahsra, I've submitted the pull request to update the batik library. Do you think you'll have time to review it soon?
Thanks!

@nahsra
Copy link
Owner

nahsra commented Aug 14, 2017

Thanks for the PR! Merged.

@nahsra nahsra closed this as completed Aug 14, 2017
@tw-mcummings
Copy link
Contributor Author

Great, thanks! Any plans for a new release of antisamy with this fix in it? I believe it would be 1.5.7.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants