Jonathan Gallimore created TOMEE-2672:
-----------------------------------------

             Summary: Update Quartz
                 Key: TOMEE-2672
                 URL: https://issues.apache.org/jira/browse/TOMEE-2672
             Project: TomEE
          Issue Type: Dependency upgrade
            Reporter: Jonathan Gallimore
            Assignee: Jonathan Gallimore


Our shaded quartz library includes a version of quartz that is vulnerable to 
CVE-2019-13990 ([https://github.com/quartz-scheduler/quartz/issues/467]). 
Although we don't have a code-path through XMLSchedulingDataProcessor, it makes 
sense to patch this as a user could theoretically use it, and libraries showing 
up with vulnerabilities can be a blocker to using TomEE.



--
This message was sent by Atlassian Jira
(v8.3.2#803003)

Reply via email to