Details
-
Bug
-
Status: Closed
-
Major
-
Resolution: Fixed
-
None
-
None
Description
Calcite depends commons-io:commons-io 2.4 – which was released on 2012-06-12 – which can be exploited to access parent directories. In recent months, there have been a fair number of releases for this package and Synk lists this as the only vulnerability it has seen.
Task is simple, bump the version to 2.7 or higher – if I may suggest just going to 2.11.0.
Attachments
Issue Links
- links to