Uploaded image for project: 'Nuxeo Platform'
  1. Nuxeo Platform
  2. NXP-32219

Upgrade logback-core to fix CVE

    XMLWordPrintable

    Details

      Description

      nuxeo-template-rendering currently has dependency on jxls version 2.12.0 which uses logback-core 1.2.10. This should be upgraded to use a minimum of logback-coreĀ 1.2.13 which fixes CVE-2023-6378.

      See results fromĀ mvn dependency:tree for LTS 2021 below:

      org.nuxeo.template.rendering:nuxeo-template-rendering-jxls:jar:2021.43-SNAPSHOT
       \- org.jxls:jxls:jar:2.12.0:compile
          \- ch.qos.logback:logback-core:jar:1.2.10:compile
      
      org.nuxeo.template.rendering:nuxeo-template-rendering-core-dependencies:pom:2021.43-SNAPSHOT
       \- org.nuxeo.template.rendering:nuxeo-template-rendering-jxls:jar:2021.43-SNAPSHOT:compile
          \- org.jxls:jxls:jar:2.12.0:compile
             \- ch.qos.logback:logback-core:jar:1.2.10:compile

        Attachments

          Activity

            People

            • Votes:
              0 Vote for this issue
              Watchers:
              3 Start watching this issue

              Dates

              • Created:
                Updated:
                Resolved: