Skip to content

Update ini4j dependency to at least 0.5.4 due to CVE-2022-41404 #566

@thomasredlin

Description

@thomasredlin

At the moment the project has multiple dependencies to org.ini4j in version 0.5.1. This library is vulnerable to CVE-2022-41404 with a CVSSv3 Base Score of HIGH (7.5).

An issue in the fetch() method in the BasicProfile class of org.ini4j before v0.5.4 allows attackers to cause a Denial of Service (DoS) via unspecified vectors.

See https://sourceforge.net/p/ini4j/bugs/56/

Please update this so INI upload is safe again.

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions