Re: Re: [jxpath] reported CVE and path forward

2022-10-17 Thread Khaled Yakdan
> > > > >>>>>> > > > > >>>>>> Get Outlook for iOS<https://aka.ms/o0ukef> > > > > >>>>>> > > > > >>>>>> From: Eric Bresie > > > > &g

Re: Re: [jxpath] reported CVE and path forward

2022-10-15 Thread Gary Gregory
done > here) > > > >>> and > > > >>>>>> bugs raised here (2)? Has (2) been done yet? > > > >>>>>> > > > >>>>>>1. > > > >>> https://commons.apache.org/prop

RE: Re: [jxpath] reported CVE and path forward

2022-10-15 Thread Khaled Yakdan
t;>>>> Get Outlook for iOS<https://aka.ms/o0ukef> > > >>>>>> > > >>>>>> From: Bruno Kinoshita > > >>>>>> Sent: Monday, October 10, 2022 4:15:03 PM > > &g

RE: Re: [jxpath] reported CVE and path forward

2022-10-10 Thread Roman Wagner
Hi all, I am working for Code Intelligence and we did our best to find a maintainer for the oss-fuzz project Unfortunately, we've have failed and got no feedback until now, but It seems to be an unmaintained project except for some typo fixes since some years. I am not sure yet to which mailing li

Re: Re: [jxpath] reported CVE and path forward

2022-10-10 Thread Bruno Kinoshita
Hi Matt, I am also subscribed to oss-fuzz for Imaging. Looks like someone added jxpath to oss-fuzz here: https://github.com/google/oss-fuzz/pull/7582 The initial oss-fuzz for ASF was, if I recall correctly, all put under a single project: https://github.com/google/oss-fuzz/tree/master/projects/a

Re: Re: [jxpath] reported CVE and path forward

2022-10-10 Thread Matt Sicker
I get emails about some of the Commons fuzzing things, but I was only aware of it being enabled for compress and imaging. On Mon, Oct 10, 2022 at 1:37 PM Roman Wagner wrote: > > Hi all, > > I am working for Code Intelligence we did our best to find a maintainer for > the oss-fuzz project. Unfortu

RE: Re: [jxpath] reported CVE and path forward

2022-10-10 Thread Roman Wagner
Hi all, I am working for Code Intelligence we did our best to find a maintainer for the oss-fuzz project. Unfortunately we've got no feedback until now, but It seems to be an unmaintained project except for some typo fixes since some years. I am not sure yet to which mailing list the bug report wa