mlsorensen opened a new issue, #6346:
URL: https://github.com/apache/cloudstack/issues/6346
##### ISSUE TYPE
* Improvement Request
##### COMPONENT NAME
~~~
LDAP
~~~
##### CLOUDSTACK VERSION
~~~
main
~~~
##### SUMMARY
LDAP test cases use packages from `org.apache.directory.server` to create an
embedded LDAP server for testing. These packages pull in ehcache 2.10.4, which
embeds a version of Jetty and Jackson that have critical vulnerabilities. While
this LDAP server and classes aren't used in a running CloudStack instance, we
should avoid packaging these classes outside of the testing scope.
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: [email protected]
For queries about this service, please contact Infrastructure at:
[email protected]