Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update ini4j dependency to at least 0.5.4 due to CVE-2022-41404 #566

Open
thomasredlin opened this issue Apr 14, 2023 · 0 comments
Open
Labels

Comments

@thomasredlin
Copy link

thomasredlin commented Apr 14, 2023

At the moment the project has multiple dependencies to org.ini4j in version 0.5.1. This library is vulnerable to CVE-2022-41404 with a CVSSv3 Base Score of HIGH (7.5).

An issue in the fetch() method in the BasicProfile class of org.ini4j before v0.5.4 allows attackers to cause a Denial of Service (DoS) via unspecified vectors.

See https://sourceforge.net/p/ini4j/bugs/56/

Please update this so INI upload is safe again.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

No branches or pull requests

1 participant