Skip to content

Replace iText 2.1.7 dependency with OpenPDF 1.0.5 [SPR-16352] #20899

@spring-projects-issues

Description

@spring-projects-issues

Andreas Røsdal opened SPR-16352 and commented

I propose to replace the iText 2.1.7 dependency in Spring (spring-webmvc) with OpenPDF 1.0.5. OpenPDF is a maintained fork of iText 4.x which still has a LGPL license. The project is maintained on GitHub: https://github.com/librepdf/openpdf

These are some references to iText 2.1.7 in Spring:
https://github.com/spring-projects/spring-framework/blob/master/spring-webmvc/spring-webmvc.gradle
https://github.com/spring-projects/spring-framework/search?utf8=%E2%9C%93&q=itext&type=

Project GitHub page:
https://github.com/librepdf/openpdf

OpenPDF contains a fix for CVE-2017-9096 iText XML External Entity Vulnerability
LibrePDF/OpenPDF#56
This sercurity vulerability has not been fixed in iText 2.1.7, since it is no longer maintained.


Issue Links:

Referenced from: commits 7a55d93

Metadata

Metadata

Assignees

Labels

in: webIssues in web modules (web, webmvc, webflux, websocket)type: taskA general task

Type

No type

Projects

No projects

Milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions