Dom4j raise up a CVE


#1

Hello everybody,

the transitive dependency dom4j 1.6.1 has a CVE, which is used by hibernate core (see http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-1000632).
I noticed that the version is very old (year 2006). Why is not the latest org.dom4j 2.x.x used?
The newest version 2.1.1 has this CVE too, but i hope in the next version it will be fixed.

Thanks and cheers

Dennis

EDIT: The dom4j 2.1.1 fixed this issue


#2

Thanks for the heads up. Please create a Jira issue for this. Thanks.


#3

Created: https://hibernate.atlassian.net/browse/HHH-12964


#4

PR: https://github.com/hibernate/hibernate-orm/pull/2525


#5

Thanks for the issue and Pull Request.