I created an issue for the CVE mentioned in the title, it is something to do with metabase v0.63.14.2 using an out-of-date version of Apache Tika Core. My org and I want to roll out an up-to-date version of Metabase to production but this one CVE blocks the pipeline from deploying it successfully. Our scanner picked it up and it is of high severity. I hope this is the right place to bring it up; can we get an ETA on when the dependency update can be merged to master?