Issues
1 of 1
Apache Commons IO Security Update: CVE-2021-29425
Fixed
Description
Acceptance / Success Criteria
None
Lucidchart Diagrams
Details
Details
Assignee
Benjamin Reed
Benjamin ReedReporter
Benjamin Reed
Benjamin ReedLabels
Sprint
None
Affects versions
Priority
PagerDuty
PagerDuty
Created May 5, 2021 at 7:15 PM
Updated May 18, 2021 at 7:47 PM
Resolved May 5, 2021 at 8:43 PM
Activity
Show:
Benjamin Reed May 5, 2021 at 8:43 PM
fixed in foundation-2018
Apache Commons IO has a CVE recommending updating to 2.7 or higher. I've marked this as a minor priority since we do not use the affected API directly (
FileNameUtils.normalize
) but without auditing everything dependencies do, it's best to upgrade just in case.