[
https://issues.apache.org/jira/browse/TIKA-3690?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17505224#comment-17505224
]
PJ Fanning commented on TIKA-3690:
----------------------------------
I created https://bz.apache.org/bugzilla/show_bug.cgi?id=65950
> upgrade to poi 5.2.1
> --------------------
>
> Key: TIKA-3690
> URL: https://issues.apache.org/jira/browse/TIKA-3690
> Project: Tika
> Issue Type: Improvement
> Components: parser
> Reporter: PJ Fanning
> Priority: Major
> Fix For: 2.3.1, 1.28.2
>
>
> There is a POI CVE that may or may not affect TIka -
> https://lists.apache.org/thread/hqc0ohg0z1j0p4ysm3y4ct6g2d8sjc2b
> Generally, probably a good idea to upgrade anyway
--
This message was sent by Atlassian Jira
(v8.20.1#820001)