pentaho / pentaho-reporting

Java class library for generating reports.
Other
283 stars 364 forks source link

Apache Poi Vulnerability #1549

Open MarijanaTR opened 1 year ago

MarijanaTR commented 1 year ago

Apache poi library has 4 direct known high vulnerabilities apachepoi Can the version be updated to at least 3.17 or higher?

lucboudreau commented 1 year ago

@MarijanaTR - Apache POI was upgraded to version 4.1.1 more than 2 years ago. Can you give us more details on where you are seeing a 3.X version?

https://github.com/pentaho/pentaho-reporting/blame/b74afabb970d933f4d4b8dd8094d60087b436443/pom.xml#L45

smmribeiro commented 1 year ago

@MarijanaTR and @lucboudreau: Apache POI was upgraded to 3.17 with pentaho-reporting#1108 and this was for 8.1 GA... We're using 4.1.1 since 9.2 GA.

tiago-s-vieira-alb commented 10 months ago

Hi, I think @MarijanaTR wanted to say POI 5.17 at least. Can you upgrade to the last POI version? (25 November 2023 - POI 5.2.5 available)