Jasperreports uses Commons-collections 3.2.1 which contains a vulnerability for a possible remote code execution.
http://www.kb.cert.org/vuls/id/576313
https://issues.apache.org/jira/browse/COLLECTIONS-580
This needs to be upgraded to 3.2.2. It seems Jasperreports does not expose this vulnerability but it leads to dependency issues when used together with other libraries that are updated.
Recommended Comments
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now