On 31/07/2017 13:36, Colm O hEigeartaigh wrote:
This is a vote to release Apache CXF 2.6.17. This is a once-off release to
fix some security advisories that have been fixed in more recent versions
of CXF. There will be no more releases on this branch. CXF users should try
as much as possible to upgrade to a supported version of CXF.
The advisories fixed in this release are as follows:
- CVE-2014-3577
- CVE-2014-3623
- CVE-2015-5253
- CVE-2016-8739
- CVE-2016-6812
- CVE-2017-5656
Artifacts:
https://repository.apache.org/content/repositories/orgapachecxf-1096/
Source:
https://repository.apache.org/content/repositories/orgapachecxf-1096/org/apache/cxf/apache-cxf/2.6.17/
Git tag:
https://git-wip-us.apache.org/repos/asf?p=cxf.git;a=commit;h=03b40aa269900098531821e6782f4966e5929307
+1
Regards.
--
Francesco Chicchiriccò
Tirasa - Open Source Excellence
http://www.tirasa.net/
Member at The Apache Software Foundation
Syncope, Cocoon, Olingo, CXF, OpenJPA, PonyMail
http://home.apache.org/~ilgrosso/