--
You received this message because you are subscribed to the Google Groups "ESAPI Project Users" group.
To unsubscribe from this group and stop receiving emails from it, send an email to esapi-project-u...@owasp.org.
To view this discussion on the web visit https://groups.google.com/a/owasp.org/d/msgid/esapi-project-users/1ea679a6-ea1c-4eee-8523-ac5da3e4f7eco%40owasp.org.
Synk has already created 3 or 4 PRs to address outdated 3rd party libraries. I just have to run our JUnit test suite to make sure nothing breaks.In the meantime, rest assured that while we pull in versions directly from our pom.xml (because at the time, AntiSamy was not being updated and I was trying to work around some other Batik related CVEs), OWASP has no direct dependency on Batik. It is actually a transitive dependency of AntiSamy. So if you avoid the ESAPI classes / methods that do not use AntiSamy, you are not exposed to this CVE via ESAPI.I hope to set some time this weekend to get the release notes into shape and get a release out by the end of the month.-kevin
--
Blog: http://off-the-wall-security.blogspot.com/ | Twitter: @KevinWWall
NSA: All your crypto bit are belong to us.
On Fri, Jun 19, 2020, 01:44 Aditya Walvekar <aditya...@gmail.com> wrote:
Hi,--Our application is using the latest ESAPI version (2.2.0.0).Recently there has been a Server Side request forgery vulnerability reported for Apache batik <= 1.12.Since ESAPI uses Apache Batik css version 1.11 , so the application is exposed to the vulnerability .So just wanted to know if there is any plan from ESAPI side to upgrade the version of Apache Batik to 1.13 which can mitigate this vulnerability.Vulnerability :Thanks and RegardsAditya
You received this message because you are subscribed to the Google Groups "ESAPI Project Users" group.
To unsubscribe from this group and stop receiving emails from it, send an email to esapi-project-users+unsub...@owasp.org.
To unsubscribe from this group and stop receiving emails from it, send an email to esapi-project-u...@owasp.org.
To view this discussion on the web visit https://groups.google.com/a/owasp.org/d/msgid/esapi-project-users/1ea679a6-ea1c-4eee-8523-ac5da3e4f7eco%40owasp.org.
--
You received this message because you are subscribed to the Google Groups "ESAPI Project Users" group.
To unsubscribe from this group and stop receiving emails from it, send an email to esapi-project-u...@owasp.org.
To view this discussion on the web visit https://groups.google.com/a/owasp.org/d/msgid/esapi-project-users/883eeea5-972b-47d4-955b-bb282d120025o%40owasp.org.