ActiveCampaign / postmark-java

Official Java client library for the Postmark HTTP API
https://postmarkapp.com
MIT License
35 stars 21 forks source link

Apache Tika vulnerabilities #39

Closed eugene-sy closed 2 years ago

eugene-sy commented 2 years ago

The version of Apache Tika currently used in the latest release has 2 known vulnerabilities: CVE-2022-25169 and CVE-2022-30126. The second one seems to be critical for the use-case in the project. Both issues are fixed in version 2.4.0. If my assumption is correct, could we have a security fix release?

ibalosh commented 2 years ago

Thank you for reporting this @eugene-sy

we will see to update the library soon

ibalosh commented 2 years ago

fixed in version 1.8.1