Copied to clipboard

Flag this post as spam?

This post will be reported to the moderators as potential spam to be looked at


  • Erik Eelman 81 posts 321 karma points
    Jan 31, 2022 @ 08:11
    Erik Eelman
    0

    Update package Sharpziplib

    Hi,

    Does anyone know if it is safe to update the package SharpZipLib from 0.86 to lastest (1.3.3) or will i break things in Umbraco search / lucene? I'm running umbraco v8.16.

    I can see that Lucene.net has a dependency to this package but a recent security scan on our projects shows that there is a vulnerability in this version of the package.

    Erik

  • Tony Fordham 3 posts 74 karma points
    May 10, 2022 @ 10:42
    Tony Fordham
    0

    Hi Erik

    Did you successfully upgrade this package? I have the same issue - a security scan has thrown up a vulnerability in the old version of SharpZipLib and I'd like to upgrade it to 1.3.3 to remediate the vulnerability. I'd be interested to hear whether you went ahead without issues.

    We're also running Umbraco 8.

  • Erik Eelman 81 posts 321 karma points
    May 19, 2022 @ 08:09
    Erik Eelman
    0

    Hi Tony,

    We succesfully upgraded this package and haven't seen any issue so far.

  • Tony Fordham 3 posts 74 karma points
    May 19, 2022 @ 08:11
    Tony Fordham
    1

    Thanks Erik. We took the plunge also in the end, since we had time pressure to remove the vulnerability. Like you, no issues so far.

    Thanks for responding :)

  • iqb-dawn 21 posts 101 karma points
    May 19, 2022 @ 14:35
    iqb-dawn
    0

    Anything officially said about how to fix this package as this is a security vulnerability in Umbraco CMS(which depends upon SharpZipLib)?

Please Sign in or register to post replies

Write your reply to:

Draft