Skip to content

update commons-fileupload2-2.0.0-M1 to commons-fileupload2-servlet5-2…#53

Open
HiddenAlx wants to merge 1 commit intoweblegacy:mainfrom
HiddenAlx:fix-issue-51
Open

update commons-fileupload2-2.0.0-M1 to commons-fileupload2-servlet5-2…#53
HiddenAlx wants to merge 1 commit intoweblegacy:mainfrom
HiddenAlx:fix-issue-51

Conversation

@HiddenAlx
Copy link

fixes issue #51
additionally fixes CVE-2025-48976
Update commons-fileupload2 v2.0.0-M1 to commons-fileupload2-jakarta-servlet5 v2.0.0-M4. Versions before M4 has CVE-2025-48976 vulnerability.
I decided to upgrade commons-fileupload2 to commons-jakarta-servlet5 instead of jakarta-servlet6 because the readme states that Struts v1.5 only supports Servlet 5 specification.
Additionally, I had to upgrade commons-io to version 2.19.

….0.0-M4 (fix CVE-2025-48976)

bump dependency commons-io from 2.15.1 to 2.19
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant