rbeckman-nextgen / test-mc

test-migration
1 stars 0 forks source link

Update to PDFBox 2.0.6 #4113

Open rbeckman-nextgen opened 4 years ago

rbeckman-nextgen commented 4 years ago

PDFBox 1.8 is still in use, and latest is 2.0.6.

2.0.0 was released 2016-04-16.

There is a migration guide from 1.8.x: https://pdfbox.apache.org/2.0/migration.html

Imported Issue. Original Details: Reporter: cschultz@chadis.com Created: 2017-07-19T13:58:44.000-0700

rbeckman-nextgen commented 4 years ago

2.0.14, now.

Imported Comment. Original Details: Author: cschultz@chadis.com Created: 2019-04-04T13:26:22.000-0700

rbeckman-nextgen commented 4 years ago

Of course, as soon as I posted the note about 2.0.14, it's found to have a vulnerability and 2.0.15 is the latest.

Note that 1.8.4, the version currently-bundled with Mirth Connect, contains this same vulnerability which can be used as a DOS on a server.

https://lists.apache.org/thread.html/a9760973a873522f4d4c0a99916ceb74f361d91006b663a0a418d34a@%3Cannounce.apache.org%3E

Imported Comment. Original Details: Author: cschultz@chadis.com Created: 2019-04-17T09:22:32.000-0700