Uploaded image for project: 'Karaf'
  1. Karaf
  2. KARAF-7737

Stepup to use latest commons-fileupload

    XMLWordPrintableJSON

Details

    • Task
    • Status: Resolved
    • Minor
    • Resolution: Fixed
    • 4.4.3
    • 4.4.3, 4.3.10
    • karaf

    Description

      We use latest Apache Karaf runtime 4.4.3. Our security scanners flag CVE-2023-24988 on this because the karaf.webconsole https://mvnrepository.com/artifact/org.apache.karaf.webconsole/org.apache.karaf.webconsole.console/4.4.3 uses vulnerable commons-fileupload 1.4

       

      There is new version of this fileupload which is clear from the CVE. So please stepup to the newer version in the upcoming Karaf release.

      Attachments

        Activity

          People

            jbonofre Jean-Baptiste Onofré
            karthickm512 Karthick
            Votes:
            0 Vote for this issue
            Watchers:
            2 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: