[
https://issues.apache.org/jira/browse/TOMEE-4127?focusedWorklogId=833951&page=com.atlassian.jira.plugin.system.issuetabpanels:worklog-tabpanel#worklog-833951
]
ASF GitHub Bot logged work on TOMEE-4127:
-----------------------------------------
Author: ASF GitHub Bot
Created on: 15/Dec/22 19:36
Start Date: 15/Dec/22 19:36
Worklog Time Spent: 10m
Work Description: rzo1 commented on PR #988:
URL: https://github.com/apache/tomee/pull/988#issuecomment-1353612061
No intention to merge this eagerly in. If we want to be save, I can change
it to "draft", so it does not accidently get merged in.
Currently, I am waiting for the normal PR CI results (full build) and the
merge of the "revert of the revert" (i.e. MP tracing fixes) by JL. Afterwards,
I am happy to run the tck.
Issue Time Tracking
-------------------
Worklog Id: (was: 833951)
Time Spent: 0.5h (was: 20m)
> CXF 3.5.5
> ---------
>
> Key: TOMEE-4127
> URL: https://issues.apache.org/jira/browse/TOMEE-4127
> Project: TomEE
> Issue Type: Dependency upgrade
> Components: TomEE Core Server
> Affects Versions: 9.0.0.RC1
> Reporter: Richard Zowalla
> Assignee: Richard Zowalla
> Priority: Major
> Time Spent: 0.5h
> Remaining Estimate: 0h
>
> December 13, 2022 - Apache CXF 3.5.5 and 3.4.10 released!
> The Apache CXF team is proud to announce the availability of our latest patch
> releases! Over 9 JIRA issues were fixed for 3.5.5 and 3.4.10. Two new CVEs
> were issued for vulnerabilities fixed in these releases:
> CVE-2022-46363: Apache CXF directory listing / code exfiltration
> CVE-2022-46364: Apache CXF SSRF Vulnerability
--
This message was sent by Atlassian Jira
(v8.20.10#820010)