on ‎2025 Mar 07 4:40 PM
Hello
Regarding Crystal report for eclipse (java) - SP31;
Looks like there is vulnerability CVE-2024-21742 in file:
lib/xmlconnector.jar/lib/apache-mime4j-core-0.8.9.jar
version 0.8.10 and beyond does not have this vulnerability:
https://mvnrepository.com/artifact/org.apache.james/apache-mime4j-core
CVE details:
Improper input validation allows for header injection in MIME4J library when using MIME4J DOM for composing message. This can be exploited by an attacker to add unintended headers to MIME messages.
Can someone confirm if this is effected by this CVE, and if so can this be a hotfix or new service pack?
Thank you!
Request clarification before answering.
I pinged R&D to comment on this one.
Often though there are reported CVE's but CR doesn't use that part so it doesn't affect the use in CR Applications.
If you have concerns for your implementation in your app you will need to show R&D how your app is vulnerable in a test app they can look at.
They are in Shanghai so it may take a few days to get a response...
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Thank you DonWilliams.
For context, xmlconnector is a file which is distributed for the crystal reports runtime for eclipse, currently we distribute all files from the lib folder with our java wrapper application. Are we saying depending on the java wrapper that jar may not be used? If so is there any information of what it is used for by crystal report engine?
Also, any update from R&D as yet?
Thank you very much!
| User | Count |
|---|---|
| 8 | |
| 5 | |
| 4 | |
| 4 | |
| 3 | |
| 3 | |
| 2 | |
| 2 | |
| 2 | |
| 2 |
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.