Menu

#102 CVE-2022-42889 - opencsv dependency on Apache Commons Text Library dependency

v1.0 (example)
closed
None
1
2022-10-20
2022-10-20
No

Hello Team,
There is a new vulnerability CVE-2022-42889 that is reported for Apache Commons Text Library include 1.5 through 1.9. Please see https://mvnrepository.com/artifact/org.apache.commons/commons-text
The latest version of opencsv is dependent on Apache Commons Text with the vulnerability. The vulnerability on the Apache Commons Text side is fixed in their latest version.
Do you have any plans to release a newer version of opencsv with the upgraded dependency for Apache Commons Text?
Thanks for developing and maintaining this lib and helping the community.

Discussion

  • Andrew Rucker Jones

    • status: open --> closed
     
  • Andrew Rucker Jones

    Closed as duplicate. Please see source merge request #34.

     
  • Andrew Rucker Jones

    • assigned_to: Glen Smith --> Andrew Rucker Jones
     

Log in to post a comment.

Want the latest updates on software, tech news, and AI?
Get latest updates about software, tech news, and AI from SourceForge directly in your inbox once a month.