QuickBooks-V3-Java-SDK icon indicating copy to clipboard operation
QuickBooks-V3-Java-SDK copied to clipboard

Dependency commons-configuration vulnerabilities

Open ddugovic opened this issue 1 year ago • 2 comments

Despite #201 being closed, https://mvnrepository.com/artifact/com.intuit.quickbooks-online/ipp-v3-java-devkit/6.4.1 depends upon commons-configuration 1.x: image

https://mvnrepository.com/artifact/commons-configuration/commons-configuration/1.10 indicates that "org.apache.commons » commons-configuration2" image image

commons-configuration 1.x also breaks my IDE, since my build stack requires commons-beanutils version 1.9.4 however commons-configuration requires commons-beanutils version 1.8.0.

ddugovic avatar Aug 30 '24 19:08 ddugovic

@ddugovic We will update the dependency and include in the next release. Thank you

ManikaSaiKiran avatar Oct 10 '24 06:10 ManikaSaiKiran

https://nvd.nist.gov/vuln/detail/CVE-2025-46392

Another CVE has been released relating to this.

mnelken avatar May 10 '25 12:05 mnelken