Skip to content

update xmlgraphics-commons to 2.6 (from 2.3)#648

Closed
sseide wants to merge 1 commit intoapache:masterfrom
sseide:update_xmlgraphics
Closed

update xmlgraphics-commons to 2.6 (from 2.3)#648
sseide wants to merge 1 commit intoapache:masterfrom
sseide:update_xmlgraphics

Conversation

@sseide
Copy link
Contributor

@sseide sseide commented Mar 5, 2021

Description

Currently used version 2.3 of xmlgraphics-commons has a security problem parsing some input with its XMPParser.

Motivation and Context

Fix medium security warning CVE-2020-11988 (https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-11988)

How Has This Been Tested?

running gradlew test and gradlew check finished with success.

Used this updated lib ourself (but we do not handle graphics with jmeter, therefore may not trigger code related to this library).

changelog of xmlgraphics-commons does not mention any problematic changes for version 2.4 and 2.6 (all releases after currently used 2.3)

Screenshots (if appropriate):

Types of changes

  • Bug fix (non-breaking change which fixes an issue)

Checklist:

  • My code follows the code style of this project.
  • I have updated the documentation accordingly.

@asfgit asfgit closed this in 54f44f5 Mar 5, 2021
@FSchumacher
Copy link
Contributor

Thanks for the PR

asfgit pushed a commit that referenced this pull request Mar 6, 2021
kkalinin pushed a commit to kkalinin/jmeter that referenced this pull request Mar 11, 2021
kkalinin pushed a commit to kkalinin/jmeter that referenced this pull request Mar 11, 2021
@sseide sseide deleted the update_xmlgraphics branch April 7, 2021 12:50
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants