[Git][security-tracker-team/security-tracker][master] Track fixed version for CVE-2019-12415/libapache-poi-java

Salvatore Bonaccorso (@carnil) carnil at debian.org
Mon Sep 21 13:29:22 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
c53a9a5b by Salvatore Bonaccorso at 2026-09-21T14:28:23+02:00
Track fixed version for CVE-2019-12415/libapache-poi-java

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -742214,7 +742214,7 @@ CVE-2019-12417 (A malicious admin user could edit the state of objects in the Ai
 CVE-2019-12416 (we got reports for 2 injection attacks against the DeltaSpike windowha ...)
 	NOT-FOR-US: DeltaSpike
 CVE-2019-12415 (In Apache POI up to 4.1.0, when using the tool XSSFExportToXml to conv ...)
-	- libapache-poi-java <unfixed> (unimportant; bug #943565)
+	- libapache-poi-java 4.1.1-1 (unimportant; bug #943565)
 	NOTE: https://www.openwall.com/lists/oss-security/2019/10/23/1
 	NOTE: Vulnerable tool not shipped in binary package
 CVE-2019-12414 (In Apache Incubator Superset before 0.32, a user can view database nam ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/c53a9a5b6e71f7f8ebdb480c003f7a6f7a99a76f

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/c53a9a5b6e71f7f8ebdb480c003f7a6f7a99a76f
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260921/9a3d9e09/attachment.htm>


More information about the debian-security-tracker-commits mailing list