Details
-
Task
-
Resolution: Done
-
Neutral
-
None
-
-
Empty show more show less
-
Yes
Description
Waiting for JackRabbit 2.20.6 which is using Tika 2.4.0 (not vulnerable for now), see also https://issues.apache.org/jira/browse/JCR-4787
Skipped 2.20.5 released on 10th March 2022 https://jackrabbit.apache.org/jcr/downloads.html#v2.20 as it has vulnerable Tika version (see BUILD-813).
Let's see if it is possible to bump Tika to a non vulnerable 2.x version, since Tika 1.x will be EoL as of 30th September 2022. https://lists.apache.org/thread/yq6n7o01kw544dvj1jsoqk29g6yqjkp3
Checklists
Attachments
Issue Links
- is duplicated by
-
BUILD-755 Update JR to 2.20.5
-
- Closed
-
- is related to
-
MGNLEESOLR-172 Exclude dependency on tika-parsers 1.x
-
- Closed
-
- relates to
-
BUILD-663 Dismiss h2 vulnerabilities
-
- Closed
-
- mentioned in
-
Page Loading...