Skip to content

chore: upgrade commons-io:commons-io#3

Draft
00felix-app[bot] wants to merge 1 commit intomasterfrom
felix/upgrade/commons-io
Draft

chore: upgrade commons-io:commons-io#3
00felix-app[bot] wants to merge 1 commit intomasterfrom
felix/upgrade/commons-io

Conversation

@00felix-app
Copy link
Copy Markdown

@00felix-app 00felix-app Bot commented Aug 6, 2025

Upgrade commons-io:commons-io from 2.5 to 2.14.0

This pull request upgrades commons-io:commons-io from version 2.5 to 2.14.0 to address multiple security vulnerabilities and ensure compliance with security best practices. The upgrade has been tested locally to confirm compatibility with existing functionality.
Vulnerabilities Addressed

Vulnerability Description
CVE-2024-47554 Apache Commons IO: Possible denial of service attack on untrusted input to XmlStreamReader. Apache Commons IO: Possible denial of service attack on untrusted input to XmlStreamReader

| CVE-2021-29425 | Path Traversal and Improper Input Validation in Apache Commons IO. Path Traversal and Improper Input Validation in Apache Commons IO |

This upgrade enhances the security and stability of the commons-io:commons-io dependency.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants