Skip to content

Conversation

@akurtakov
Copy link
Contributor

Version 6.2.7 used is vulnerable to
https://www.cve.org/CVERecord?id=CVE-2022-40152 as can be seen at https://mvnrepository.com/artifact/com.fasterxml.woodstox/woodstox-core/6.2.7
Updated stax2-api to match the requirements upstream.

Version 6.2.7 used is vulnerable to
https://www.cve.org/CVERecord?id=CVE-2022-40152 as can be seen at
https://mvnrepository.com/artifact/com.fasterxml.woodstox/woodstox-core/6.2.7
Updated stax2-api to match the requirements upstream.
@akurtakov
Copy link
Contributor Author

Latest version is https://mvnrepository.com/artifact/com.fasterxml.woodstox/woodstox-core/7.1.1 but not moving to it as I don't know when/what/how uses thus better to have a fix for the CVE now and handle the major update separately.

@Mailaender
Copy link
Member

Seems to be a dependency of @cdk.

Copy link
Member

@Mailaender Mailaender left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Molecules are still displayed.

@Mailaender Mailaender merged commit cb0a8e3 into OpenChrom:develop Jan 5, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants