update apache tika to 1.28.3 (from 1.27)

Description

 

https://downloads.apache.org/tika/1.28.1/CHANGES-1.28.1.txt

we should also offer the extended OSGI bundle 48mb which can do lots of extra detection as an extension for better mime type detection

with

Attachments

1

relates to

Activity

Jon Clausen 22 November 2022 at 22:58

No problem. Done:

Zac Spitzer 22 November 2022 at 21:00
Edited

can you file a new ticket and link to this one and the new vulns ticket?

We only use the basic detection so lucee isn’t at risk from that CVE (not that we won’t update)

Jon Clausen 22 November 2022 at 20:47

FYI. The version of org.apache.tika.core in Lucee 5.3.10 was updated to 1.28.3 but that version still is marked as vulnerable in the CVE:

Zac Spitzer 13 October 2022 at 12:02

actually 1.28.5 is available

 

Zac Spitzer 10 June 2022 at 12:35

I believe this is due to the update provider caching the meta data once

Fixed

Details

Assignee

Reporter

Labels

New Issue warning screen

Before you create a new Issue, please post to the mailing list first https://dev.lucee.org

Once the issue has been verified, one of the Lucee team will ask you to file an issue

Sprint

Fix versions

Priority

Created 26 March 2022 at 23:23
Updated 22 November 2022 at 22:58
Resolved 22 November 2022 at 21:00