jxlsteam / jxls

Java library for creating Excel reports using Excel templates
http://jxls.sourceforge.net
Apache License 2.0
395 stars 89 forks source link

Fix current CVE in JXLS 3.0.0 #322

Open uek06 opened 2 months ago

uek06 commented 2 months ago

Hello,

jxls-poi version 3.0.0 has 2 CVE from dependencies that would be easy to correct :

Is it possible to release a version 3.0.1 with theses fixes ?

Thanks

SoltauFintel commented 2 months ago

Bonjour

We can not update to POI > 5.2.2 because of the unfixed POI bug 66687.

We could try updating to commons-compress 1.26.2.