Skip to content

Conversation

@00felix
Copy link

@00felix 00felix commented Dec 23, 2025

Upgrade org.apache.james:apache-mime4j-core from 0.8.6 to 0.8.10
Upgrade org.apache.ws.commons.axiom:axiom-api from 1.4.0 to 2.0.0
Upgrade org.apache.ws.commons.axiom:axiom-impl from 1.4.0 to 2.0.0

This pull request upgrades org.apache.james:apache-mime4j-core from version 0.8.6 to 0.8.10, org.apache.ws.commons.axiom:axiom-api from version 1.4.0 to 2.0.0, and org.apache.ws.commons.axiom:axiom-impl from version 1.4.0 to 2.0.0 to address multiple security vulnerabilities and ensure compliance with security best practices. The upgrade has been tested locally to confirm compatibility with existing functionality.

Vulnerabilities Addressed

Vulnerability Description
GHSA-jw7r-rxff-gv24 Apache James MIME4J improper input validation vulnerability

This upgrade enhances the security and stability of the org.apache.james:apache-mime4j-core, org.apache.ws.commons.axiom:axiom-api, and org.apache.ws.commons.axiom:axiom-impl dependencies.

@tfr42 tfr42 added the contributor review requires review by contributor label Jan 16, 2026
@tfr42
Copy link
Member

tfr42 commented Jan 16, 2026

@00felix Thanks for contributing to the OSGeo project deegree. Since this is your first code contribution we kindly ask you to read the deegree contribution guidelines and confirm to by sending an email to the deegree users mailing list. Thanks!

Copy link
Member

@tfr42 tfr42 left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Changes required. Version shall go into dependenciesManagement section.

<groupId>org.apache.james</groupId>
<artifactId>apache-mime4j-core</artifactId>
<version>0.8.10</version>
</dependency>
Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Setting of dependency and version shall be done in the root project POM in the dependenciesManagement section. This change requires re-work.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

contributor review requires review by contributor

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants