Batch Importer (Bib/Acq) (UXPROD-47)

[ISBNUTIL-15] commons-validator 1.7 (CVE-2019-10086) Created: 02/May/22  Updated: 23/May/22  Resolved: 11/May/22

Status: Closed
Project: isbn-util
Components: None
Affects versions: None
Fix versions: 1.4.0
Parent: Batch Importer (Bib/Acq)

Type: Bug Priority: P2
Reporter: Julian Ladisch Assignee: Unassigned
Resolution: Done Votes: 0
Labels: security, security-reviewed
Remaining Estimate: Not Specified
Time Spent: Not Specified
Original estimate: Not Specified

Issue links:
Blocks
blocks ISBNUTIL-16 Release folio-isbn-util fixing Deseri... Closed
Defines
defines UXPROD-3446 NFR: Data Import R2 2022 Morning Glor... Closed
Sprint: Folijet Sprint 139
Story Points: 1
Development Team: Folijet
Release: Morning Glory (R2 2022)
Epic Link: Batch Importer (Bib/Acq)
RCA Group: Related dependency upgrade

 Description   

Upgrade commons-validator from 1.6 to 1.7. This indirectly upgrades commons-beanutils from 1.9.2 to 1.9.4 fixing Deserialization of Untrusted Data: https://nvd.nist.gov/vuln/detail/CVE-2019-10086



 Comments   
Comment by Julian Ladisch [ 02/May/22 ]

@ Folijet: Please code review and merge https://github.com/folio-org/folio-isbn-util/pull/19 . I don't have write permission for this repository.

Comment by Ann-Marie Breaux (Inactive) [ 10/May/22 ]

Aliaksandr Fedasiuk Serhii_Nosko Please see Julian's comment above. Can we include in the current sprint, or do we need to wait until next sprint? Also, which RCA Group should be assigned? Thank you!

cc: Kateryna Senchenko Ivan Kryzhanovskyi

Comment by Aliaksandr Fedasiuk [ 11/May/22 ]

Hi Julian Ladisch, your PR was approved and merged.

Comment by Aliaksandr Fedasiuk [ 11/May/22 ]

Hi Ann-Marie Breaux, after releasing folio-isbn-util we should update used version of this package in mod-inventory.

We need a task to release folio-isbn-util.

Comment by Julian Ladisch [ 11/May/22 ]

Thanks!
Please release folio-isbn-util to that the fixed version can be used by all modules that use it: https://github.com/search?l=Maven+POM&q=org%3Afolio-org+folio-isbn-util&type=Code

Comment by Julian Ladisch [ 11/May/22 ]

Release task created: ISBNUTIL-16 Closed

Comment by Ann-Marie Breaux (Inactive) [ 16/May/22 ]

Hi Aliaksandr Fedasiuk and Julian Ladisch This is for Morning Glory, right? I'll update the release fields and features and such. Even if we need to release sooner than the Morning Glory general releases, we don't have to release for a Kiwi or Lotus Hotfix, do we?

Comment by Aliaksandr Fedasiuk [ 16/May/22 ]

Hi Ann-Marie Breaux, you are right. We may release it earlier than the general Morning Glory releases, but we don't need it for Kiwi and Lotus Hotfix.

Generated at Thu Feb 08 22:25:31 UTC 2024 using Jira 1001.0.0-SNAPSHOT#100246-sha1:7a5c50119eb0633d306e14180817ddef5e80c75d.