Skip to content

PRODSEC-10332 updated fileupload2 to address CVE-2025-48976#170

Merged
jakubkochman merged 2 commits intomasterfrom
feature/PRODSEC-10332-update-vulnerable-fileupload2-core
Jun 30, 2025
Merged

PRODSEC-10332 updated fileupload2 to address CVE-2025-48976#170
jakubkochman merged 2 commits intomasterfrom
feature/PRODSEC-10332-update-vulnerable-fileupload2-core

Conversation

@jakubkochman
Copy link
Copy Markdown
Contributor

@jakubkochman jakubkochman commented Jun 30, 2025

This change addresses vulnerability in commons-fileupload2-core which is a dependency of commons-fileupload2-jakarta. That artifact is no longer maintained and divided into servlet5 and servlet6 versions separately. Because of the import path change for servlet6 version this update can't be done easily outside of surf-webscripts repository, e.g. in alfresco-enterprise.


Since the repo utilizes Veracode maven plugin, which will fail the build if high vulnerability is detected, I have took the chance to also update commons beanutils and spring libs using other already fixed alfresco repositories as example.

@jakubkochman jakubkochman force-pushed the feature/PRODSEC-10332-update-vulnerable-fileupload2-core branch from 3490018 to a713521 Compare June 30, 2025 11:12
@jakubkochman jakubkochman force-pushed the feature/PRODSEC-10332-update-vulnerable-fileupload2-core branch from a713521 to f2b817a Compare June 30, 2025 11:53
@jakubkochman jakubkochman merged commit b22bd14 into master Jun 30, 2025
3 checks passed
@jakubkochman jakubkochman deleted the feature/PRODSEC-10332-update-vulnerable-fileupload2-core branch June 30, 2025 12:29
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants