[jira] [Commented] (DIRSTUDIO-1304) vulnerability for poi-3.9.jar
[ https://issues.apache.org/jira/browse/DIRSTUDIO-1304?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17820865#comment-17820865 ] Pierre Smits commented on DIRSTUDIO-1304: - [~elecharny] I will address this soon. > vulnerability for poi-3.9.jar > - > > Key: DIRSTUDIO-1304 > URL: https://issues.apache.org/jira/browse/DIRSTUDIO-1304 > Project: Directory Studio > Issue Type: Task >Affects Versions: 2.0.0-M17 >Reporter: Krystian Tokarz >Assignee: Pierre Smits >Priority: Major > Fix For: 2.0.0-M18 > > > Our vulnerability system (Nessus) discovers that poi-3.9.jar file is > vulnerable (medium risk). This file is created when Apache Directory Studio > is started on our Windows 2016 Server OS. > Folders: > C:\Documents and > Settings\%username%\.eclipse\1407070357_win32_win32_x86_64\configuration\org.eclipse.osgi\65\0\.cp\lib\poi-3.9.jar > and > C:\Users\%username%\.eclipse\1407070357_win32_win32_x86_64\configuration\org.eclipse.osgi\65\0\.cp\lib\poi-3.9.jar > > Plugin ID: 106717 > Plugin description: The version of Apache POI installed on the remote host is > a version prior to 3.17. It is, therefore, affected by multiple DoS > vulnerabilities. Note that Nessus has not tested for these issues but has > instead relied only on the application's self-reported version number. > Apache POI < 3.17 Multiple DoS Vulnerabilities > > Could you provide any information about this issue? Can we patch this somehow? > -- This message was sent by Atlassian Jira (v8.20.10#820010) - To unsubscribe, e-mail: dev-unsubscr...@directory.apache.org For additional commands, e-mail: dev-h...@directory.apache.org
[jira] [Commented] (DIRSTUDIO-1304) vulnerability for poi-3.9.jar
[ https://issues.apache.org/jira/browse/DIRSTUDIO-1304?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17820851#comment-17820851 ] Emmanuel Lécharny commented on DIRSTUDIO-1304: -- Pierre, if it works on your machine, could you commit the change? Thanks! > vulnerability for poi-3.9.jar > - > > Key: DIRSTUDIO-1304 > URL: https://issues.apache.org/jira/browse/DIRSTUDIO-1304 > Project: Directory Studio > Issue Type: Task >Affects Versions: 2.0.0-M17 >Reporter: Krystian Tokarz >Assignee: Pierre Smits >Priority: Major > Fix For: 2.0.0-M18 > > > Our vulnerability system (Nessus) discovers that poi-3.9.jar file is > vulnerable (medium risk). This file is created when Apache Directory Studio > is started on our Windows 2016 Server OS. > Folders: > C:\Documents and > Settings\%username%\.eclipse\1407070357_win32_win32_x86_64\configuration\org.eclipse.osgi\65\0\.cp\lib\poi-3.9.jar > and > C:\Users\%username%\.eclipse\1407070357_win32_win32_x86_64\configuration\org.eclipse.osgi\65\0\.cp\lib\poi-3.9.jar > > Plugin ID: 106717 > Plugin description: The version of Apache POI installed on the remote host is > a version prior to 3.17. It is, therefore, affected by multiple DoS > vulnerabilities. Note that Nessus has not tested for these issues but has > instead relied only on the application's self-reported version number. > Apache POI < 3.17 Multiple DoS Vulnerabilities > > Could you provide any information about this issue? Can we patch this somehow? > -- This message was sent by Atlassian Jira (v8.20.10#820010) - To unsubscribe, e-mail: dev-unsubscr...@directory.apache.org For additional commands, e-mail: dev-h...@directory.apache.org
[jira] [Commented] (DIRSTUDIO-1304) vulnerability for poi-3.9.jar
[ https://issues.apache.org/jira/browse/DIRSTUDIO-1304?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17817084#comment-17817084 ] Pierre Smits commented on DIRSTUDIO-1304: - locally upgrading to latest available (5.2.5) built successfully. > vulnerability for poi-3.9.jar > - > > Key: DIRSTUDIO-1304 > URL: https://issues.apache.org/jira/browse/DIRSTUDIO-1304 > Project: Directory Studio > Issue Type: Task >Affects Versions: 2.0.0-M17 >Reporter: Krystian Tokarz >Assignee: Pierre Smits >Priority: Major > Fix For: 2.0.0-M18 > > > Our vulnerability system (Nessus) discovers that poi-3.9.jar file is > vulnerable (medium risk). This file is created when Apache Directory Studio > is started on our Windows 2016 Server OS. > Folders: > C:\Documents and > Settings\%username%\.eclipse\1407070357_win32_win32_x86_64\configuration\org.eclipse.osgi\65\0\.cp\lib\poi-3.9.jar > and > C:\Users\%username%\.eclipse\1407070357_win32_win32_x86_64\configuration\org.eclipse.osgi\65\0\.cp\lib\poi-3.9.jar > > Plugin ID: 106717 > Plugin description: The version of Apache POI installed on the remote host is > a version prior to 3.17. It is, therefore, affected by multiple DoS > vulnerabilities. Note that Nessus has not tested for these issues but has > instead relied only on the application's self-reported version number. > Apache POI < 3.17 Multiple DoS Vulnerabilities > > Could you provide any information about this issue? Can we patch this somehow? > -- This message was sent by Atlassian Jira (v8.20.10#820010) - To unsubscribe, e-mail: dev-unsubscr...@directory.apache.org For additional commands, e-mail: dev-h...@directory.apache.org
[jira] [Commented] (DIRSTUDIO-1304) vulnerability for poi-3.9.jar
[ https://issues.apache.org/jira/browse/DIRSTUDIO-1304?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17685206#comment-17685206 ] Krystian Tokarz commented on DIRSTUDIO-1304: Could you please provide any feedback? > vulnerability for poi-3.9.jar > - > > Key: DIRSTUDIO-1304 > URL: https://issues.apache.org/jira/browse/DIRSTUDIO-1304 > Project: Directory Studio > Issue Type: Task >Affects Versions: 2.0.0-M17 >Reporter: Krystian Tokarz >Priority: Major > Fix For: 2.0.0-M18 > > > Our vulnerability system (Nessus) discovers that poi-3.9.jar file is > vulnerable (medium risk). This file is created when Apache Directory Studio > is started on our Windows 2016 Server OS. > Folders: > C:\Documents and > Settings\%username%\.eclipse\1407070357_win32_win32_x86_64\configuration\org.eclipse.osgi\65\0\.cp\lib\poi-3.9.jar > and > C:\Users\%username%\.eclipse\1407070357_win32_win32_x86_64\configuration\org.eclipse.osgi\65\0\.cp\lib\poi-3.9.jar > > Plugin ID: 106717 > Plugin description: The version of Apache POI installed on the remote host is > a version prior to 3.17. It is, therefore, affected by multiple DoS > vulnerabilities. Note that Nessus has not tested for these issues but has > instead relied only on the application's self-reported version number. > Apache POI < 3.17 Multiple DoS Vulnerabilities > > Could you provide any information about this issue? Can we patch this somehow? > -- This message was sent by Atlassian Jira (v8.20.10#820010) - To unsubscribe, e-mail: dev-unsubscr...@directory.apache.org For additional commands, e-mail: dev-h...@directory.apache.org
[jira] [Commented] (DIRSTUDIO-1304) vulnerability for poi-3.9.jar
[ https://issues.apache.org/jira/browse/DIRSTUDIO-1304?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17610477#comment-17610477 ] Emmanuel Lécharny commented on DIRSTUDIO-1304: -- Moved to DIRSTUDIO where it belongs. Stefan, I think we should move to a more recent version of {{poi}}, the current one is {{5.2.3}}. > vulnerability for poi-3.9.jar > - > > Key: DIRSTUDIO-1304 > URL: https://issues.apache.org/jira/browse/DIRSTUDIO-1304 > Project: Directory Studio > Issue Type: Task >Affects Versions: 2.0.0-M17 >Reporter: Krystian Tokarz >Priority: Major > Fix For: 2.0.0-M17, 2.0.0 > > > Our vulnerability system (Nessus) discovers that poi-3.9.jar file is > vulnerable (medium risk). This file is created when Apache Directory Studio > is started on our Windows 2016 Server OS. > Folders: > C:\Documents and > Settings\%username%\.eclipse\1407070357_win32_win32_x86_64\configuration\org.eclipse.osgi\65\0\.cp\lib\poi-3.9.jar > and > C:\Users\%username%\.eclipse\1407070357_win32_win32_x86_64\configuration\org.eclipse.osgi\65\0\.cp\lib\poi-3.9.jar > > Plugin ID: 106717 > Plugin description: The version of Apache POI installed on the remote host is > a version prior to 3.17. It is, therefore, affected by multiple DoS > vulnerabilities. Note that Nessus has not tested for these issues but has > instead relied only on the application's self-reported version number. > Apache POI < 3.17 Multiple DoS Vulnerabilities > > Could you provide any information about this issue? Can we patch this somehow? > -- This message was sent by Atlassian Jira (v8.20.10#820010) - To unsubscribe, e-mail: dev-unsubscr...@directory.apache.org For additional commands, e-mail: dev-h...@directory.apache.org