[ https://issues.apache.org/jira/browse/DIRSTUDIO-1304?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ]
Pierre Smits closed DIRSTUDIO-1304. ----------------------------------- > vulnerability for poi-3.9.jar > ----------------------------- > > Key: DIRSTUDIO-1304 > URL: https://issues.apache.org/jira/browse/DIRSTUDIO-1304 > Project: Directory Studio > Issue Type: Task > Affects Versions: 2.0.0-M17 > Reporter: Krystian Tokarz > Assignee: Pierre Smits > Priority: Major > Fix For: 2.0.0-M18 > > > Our vulnerability system (Nessus) discovers that poi-3.9.jar file is > vulnerable (medium risk). This file is created when Apache Directory Studio > is started on our Windows 2016 Server OS. > Folders: > C:\Documents and > Settings\%username%\.eclipse\1407070357_win32_win32_x86_64\configuration\org.eclipse.osgi\65\0\.cp\lib\poi-3.9.jar > and > C:\Users\%username%\.eclipse\1407070357_win32_win32_x86_64\configuration\org.eclipse.osgi\65\0\.cp\lib\poi-3.9.jar > > Plugin ID: 106717 > Plugin description: The version of Apache POI installed on the remote host is > a version prior to 3.17. It is, therefore, affected by multiple DoS > vulnerabilities. Note that Nessus has not tested for these issues but has > instead relied only on the application's self-reported version number. > Apache POI < 3.17 Multiple DoS Vulnerabilities > > Could you provide any information about this issue? Can we patch this somehow? > -- This message was sent by Atlassian Jira (v8.20.10#820010) --------------------------------------------------------------------- To unsubscribe, e-mail: dev-unsubscr...@directory.apache.org For additional commands, e-mail: dev-h...@directory.apache.org