Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update dependency to flying-saucer-pdf-openpdf version 9.1.11 #558

Closed
ghost opened this issue Jan 8, 2018 · 3 comments
Closed

Update dependency to flying-saucer-pdf-openpdf version 9.1.11 #558

ghost opened this issue Jan 8, 2018 · 3 comments

Comments

@ghost
Copy link

ghost commented Jan 8, 2018

I recommend that you replace the dependency from flying-saucer-pdf (iText 2.x) to flying-saucer-pdf-openpdf 9.1.11.

This would use the Flying Saucer library with OpenPDF:
https://github.com/librepdf/openpdf

iText 2.x has unfixed security bugs, so it is best to replace it with OpenPDF.
http://seclists.org/bugtraq/2017/Nov/20
LibrePDF/OpenPDF#56

See some more information here also:
https://github.com/flyingsaucerproject/flyingsaucer
https://mvnrepository.com/artifact/org.xhtmlrenderer/flying-saucer-pdf-openpdf

(This is configured in dependencies.gradle - https://github.com/alkacon/opencms-core/blob/branch_10_5_x/dependencies.gradle#L166)

@ghost
Copy link
Author

ghost commented Jan 23, 2018

See: #566

@tHerrmann
Copy link

The flying saucer dependency has been updated in branch_10_5_x.

@tHerrmann
Copy link

This has been fixed with release 10.5.4.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

1 participant