Skip to content

Conversation

@SoumyajitPatra
Copy link

Dependency: xmlbeans-2.6.0.jar
Vulnerability IDs: cpe:2.3:a:apache:xmlbeans:2.6.0:::::::*
Package: pkg:maven/org.apache.xmlbeans/xmlbeans@2.6.0
Highest Severity: CRITICAL

xmlbeans@2.6.0 is introduced by poi-ooxml@3.17. On upgrading to poi-ooxml@4.0.0 we get xmlbeans@3.0.0 which does not have any OWASP vulnerability

@SoumyajitPatra SoumyajitPatra changed the title Fix OWASP Critical Vulnerability in dependency xmlbeans-2.6.0.jar Fix OWASP Critical Vulnerability from dependency xmlbeans-2.6.0.jar Apr 7, 2022
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants