Jonathan Gallimore created TOMEE-2672:
-----------------------------------------
Summary: Update Quartz
Key: TOMEE-2672
URL: https://issues.apache.org/jira/browse/TOMEE-2672
Project: TomEE
Issue Type: Dependency upgrade
Reporter: Jonathan Gallimore
Assignee: Jonathan Gallimore
Our shaded quartz library includes a version of quartz that is vulnerable to
CVE-2019-13990 ([https://github.com/quartz-scheduler/quartz/issues/467]).
Although we don't have a code-path through XMLSchedulingDataProcessor, it makes
sense to patch this as a user could theoretically use it, and libraries showing
up with vulnerabilities can be a blocker to using TomEE.
--
This message was sent by Atlassian Jira
(v8.3.2#803003)