JBoss List Archives
Sign In
Sign Up
Sign In
Sign Up
Manage this list
2026
April
March
February
January
2025
December
November
October
September
August
July
June
May
April
March
February
January
2024
December
November
October
September
August
July
June
May
April
March
February
January
2023
December
November
October
September
August
July
June
May
April
March
February
January
2022
December
November
October
September
August
July
June
May
April
March
February
January
2021
December
November
October
September
August
July
June
May
April
March
February
January
2020
December
November
October
September
August
July
June
May
April
March
February
January
2019
December
November
October
September
August
July
June
May
April
March
February
January
2018
December
November
October
September
August
July
June
May
April
March
February
January
2017
December
November
October
September
August
July
June
May
April
March
February
January
2016
December
November
October
September
August
July
June
May
April
March
February
January
2015
December
November
October
September
August
July
June
May
April
March
February
January
2014
December
November
October
September
August
July
June
May
April
March
February
January
2013
December
November
October
September
August
July
June
May
April
March
February
January
2012
December
November
October
September
August
July
June
May
April
March
February
January
2011
December
November
October
September
August
July
June
May
April
March
February
January
2010
December
November
October
September
August
July
June
May
April
March
February
January
2009
December
November
October
September
August
July
June
May
April
March
February
January
2008
December
November
October
September
August
July
June
May
April
March
February
January
2007
December
November
October
September
August
July
June
May
April
March
February
January
2006
December
November
October
September
August
List overview
Download
thread
[hibernate-issues] [JIRA] (HHH-14018) Upgrade to dom4j 2.1.3 for CVE-2020-10683
Frans Flippo (JIRA)
Wednesday, 13 May 2020
Wed, 13 May '20
7:16 a.m.
Frans Flippo (
https://hibernate.atlassian.net/secure/ViewProfile.jspa?accountId=5dadc79...
) *updated* an issue Hibernate ORM (
https://hibernate.atlassian.net/browse/HHH?atlOrigin=eyJpIjoiZWJhYmZiY2Uz...
) / Bug (
https://hibernate.atlassian.net/browse/HHH-14018?atlOrigin=eyJpIjoiZWJhYm...
) HHH-14018 (
https://hibernate.atlassian.net/browse/HHH-14018?atlOrigin=eyJpIjoiZWJhYm...
) Upgrade to dom4j 2.1.3 for CVE-2020-10683 (
https://hibernate.atlassian.net/browse/HHH-14018?atlOrigin=eyJpIjoiZWJhYm...
) Change By: Frans Flippo (
https://hibernate.atlassian.net/secure/ViewProfile.jspa?accountId=5dadc79...
) h2. Overview the transitive dependency dom4j 1 2. 6. 1 has a CVE, which. is used by a dependency of hibernate core and has a CVE (see [
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-
2020-10683)|http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-
2018-1000632) ]. This version is outdated. Hibernate core shoould should upgrade to version 2. x 1. x 3 or later. org.dom4j h2. Detail Related to the forum
https://discourse.hibernate.org/t/dom4j-raise-up-a-cve/1362
. (
https://hibernate.atlassian.net/browse/HHH-14018#add-comment?atlOrigin=ey...
) Add Comment (
https://hibernate.atlassian.net/browse/HHH-14018#add-comment?atlOrigin=ey...
) Get Jira notifications on your phone! Download the Jira Cloud app for Android (
https://play.google.com/store/apps/details?id=com.atlassian.android.jira....
) or iOS (
https://itunes.apple.com/app/apple-store/id1006972087?pt=696495&ct=Em...
) This message was sent by Atlassian Jira (v1001.0.0-SNAPSHOT#100126- sha1:dd08494 )
Attachments:
attachment.html
(text/html — 18.6 KB)
0
/
0
Reply
Back to the thread
Back to the list