Skip to content

2.5.4.0 and CVE-2024-29131, 33. #843

Answered by kwwall
kumakaori asked this question in Q&A
Discussion options

You must be logged in to vote

@kumakaori asked:

Based on this information, and building on what's been written at #748, is this a tipping point where ESAPI will consider updating to org.apache.commons : commons-configuration2 : 2.10.1?

I started down that path the evening of Wed, 5/29, when I first ran Dependency Check and saw that it reported those 2 CVEs. I figured it would be faster to just patch it than to do a full-deep dive analysis to see if they were truly false positives as I expected. It was easy enough to get ESAPI to compile the AccessController using org.apache.commons : commons-configuration2 : 2.10.1, but getting the regression tests to pass was an ordeal. It was bad enough that I felt like I was comi…

Replies: 4 comments 1 reply

Comment options

You must be logged in to vote
0 replies
Comment options

You must be logged in to vote
0 replies
Comment options

You must be logged in to vote
0 replies
Answer selected by kumakaori
Comment options

You must be logged in to vote
1 reply
@kwwall
Comment options

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants