intive-FDV / DynamicJasper

Dynamic Reports using Jasper Reports
http://intive-fdv.github.io/DynamicJasper/
GNU Lesser General Public License v3.0
241 stars 128 forks source link

Fixes CVE-2020-11988 #119

Closed 123Haynes closed 2 years ago

123Haynes commented 2 years ago

This commit updates org.apache.xmlgraphics:xmlgraphics-commons to version 2.6 to adress the open CVE.
See https://security.snyk.io/vuln/SNYK-JAVA-ORGAPACHEXMLGRAPHICS-1079038 for more information about it.
It alo updates the supported jasperreports version to 6.18.1 so we can enjoy the bugfixes and improvements.

arlandgoh commented 2 years ago

@juanalvarezg are you going to merge and release this branch?

123Haynes commented 2 years ago

looks like this has been fixed in https://github.com/intive-FDV/DynamicJasper/commit/20eb441dd33e4f92a6b5c08b4682c6e556c3bcac