Skip to content

Conversation

alchemainapp[bot]
Copy link

@alchemainapp alchemainapp bot commented Aug 6, 2025

Upgrade org.apache.poi:poi from 3.10-FINAL to 4.1.1

This pull request upgrades org.apache.poi:poi from version 3.10-FINAL to 4.1.1 to address multiple security vulnerabilities and ensure compliance with security best practices. The upgrade has been tested locally to confirm compatibility with existing functionality.
Vulnerabilities Addressed

Vulnerability Description
CVE-2014-3574 Improper Input Validation in Apache POI. Improper Input Validation in Apache POI

| CVE-2014-3529 | Improper Restriction of XML External Entity Reference in Apache POI. Improper Restriction of XML External Entity Reference in Apache POI |

| CVE-2014-9527 | Loop with Unreachable Exit Condition in Apache POI. Loop with Unreachable Exit Condition in Apache POI |

| CVE-2017-5644 | Improper Restriction of Recursive Entity References in DTDs in Apache POI. Improper Restriction of Recursive Entity References in DTDs in Apache POI |

| CVE-2017-12626 | Denial of Service in Apache POI. Denial of Service in Apache POI |

| CVE-2019-12415 | Improper Restriction of XML External Entity Reference in Apache POI. Improper Restriction of XML External Entity Reference in Apache POI |

This upgrade enhances the security and stability of the org.apache.poi:poi dependency.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

0 participants