Merge pull request #9832 from dataease/pr@dev@fix_security

fix: poi以及cas-client安全漏洞
This commit is contained in:
fit2cloud-chenyw 2024-05-24 11:29:25 +08:00 committed by GitHub
commit b327f7ccec
No known key found for this signature in database
GPG Key ID: B5690EEEBB952194
2 changed files with 40 additions and 1 deletions

39
pom.xml
View File

@ -10,6 +10,7 @@
<properties>
<dataease.version>1.18.19</dataease.version>
<poi.version>4.1.1</poi.version>
</properties>
<name>dataease</name>
@ -27,6 +28,44 @@
<relativePath/>
</parent>
<dependencyManagement>
<dependencies>
<dependency>
<groupId>org.apache.poi</groupId>
<artifactId>poi</artifactId>
<version>${poi.version}</version>
<exclusions>
<exclusion>
<groupId>*</groupId>
<artifactId>*</artifactId>
</exclusion>
</exclusions>
</dependency>
<dependency>
<groupId>org.apache.poi</groupId>
<artifactId>poi-ooxml</artifactId>
<version>${poi.version}</version>
<exclusions>
<exclusion>
<groupId>*</groupId>
<artifactId>*</artifactId>
</exclusion>
</exclusions>
</dependency>
<dependency>
<groupId>org.apache.poi</groupId>
<artifactId>poi-ooxml-schemas</artifactId>
<version>${poi.version}</version>
<exclusions>
<exclusion>
<groupId>*</groupId>
<artifactId>*</artifactId>
</exclusion>
</exclusions>
</dependency>
</dependencies>
</dependencyManagement>
<build>
<plugins>
<plugin>

View File

@ -19,7 +19,7 @@
<dependency>
<groupId>org.jasig.cas.client</groupId>
<artifactId>cas-client-core</artifactId>
<version>3.5.0</version>
<version>3.6.4</version>
</dependency>
<dependency>