-
Component Upgrade
-
Resolution: Done
-
Major
-
5.0.9.Final
-
None
-
None
Tag: https://github.com/apache/james-mime4j/releases/tag/apache-mime4j-project-0.8.11
Diff: https://github.com/apache/james-mime4j/compare/apache-mime4j-project-0.8.10...apache-mime4j-project-0.8.11
[[INFO] | | \- org.jboss.resteasy:resteasy-multipart-provider:jar:5.0.9.Final:compile [INFO] | | +- org.apache.james:apache-mime4j-dom:jar:0.8.9:compile [INFO] | | | \- org.apache.james:apache-mime4j-core:jar:0.8.9:compile [INFO] | | \- org.apache.james:apache-mime4j-storage:jar:0.8.9:compile
resteasy-multipart-provider:jar:5.0.9.Final depends upon a version of mime4j which appears to be vulnerable, see
https://cve.mitre.org/cgi-bin/cvename.cgi?name=2024-21742
https://lists.apache.org/thread/nrqzg93219wdj056pqfszsd33dc54kfy
- clones
-
RESTEASY-3274 Upgrade mime4j to a more recent version
- Resolved