|
Administrator
|
Hi,
These old JARs are used to support Pellet.
If you don't need Pellet, you can just remove the JARs.
If you do need Pellet, it's more complicated... we need to manage to recompile Pellet with updated/fixed JARs, which is not an easy task : updating from version 2.10 to 4.2 is a big leap :-(
Another solution would be to delete the support for XML entity in the JARs (I think Owlready don't use them), which would prevent the vulnerability ?
Jiba
|