Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Vulnerability on sanselan dependency #7453

Closed
bmarty opened this issue Oct 26, 2022 · 0 comments · Fixed by #7454
Closed

Vulnerability on sanselan dependency #7453

bmarty opened this issue Oct 26, 2022 · 0 comments · Fixed by #7454
Assignees
Labels
O-Occasional Affects or can be seen by some users regularly or most users rarely S-Minor Impairs non-critical functionality or suitable workarounds exist Security T-Task Refactoring, enabling or disabling functionality, other engineering tasks

Comments

@bmarty
Copy link
Member

bmarty commented Oct 26, 2022

Reported by Sonatype Lift:

image

We are using this library to strip Exif data. Maybe find another library to do it, since this version is 14 years old (so maybe not maintained anymore). https://github.com/apache/commons-imaging could be a good candidate or https://developer.android.com/jetpack/androidx/releases/exifinterface ?
Commit which introduced it: aea2220

@bmarty bmarty added Security S-Minor Impairs non-critical functionality or suitable workarounds exist O-Occasional Affects or can be seen by some users regularly or most users rarely T-Task Refactoring, enabling or disabling functionality, other engineering tasks labels Oct 26, 2022
@bmarty bmarty self-assigned this Oct 26, 2022
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
O-Occasional Affects or can be seen by some users regularly or most users rarely S-Minor Impairs non-critical functionality or suitable workarounds exist Security T-Task Refactoring, enabling or disabling functionality, other engineering tasks
Projects
None yet
1 participant