[
https://issues.apache.org/jira/browse/UNOMI-821?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17821072#comment-17821072
]
Serge Huber commented on UNOMI-821:
-----------------------------------
Thanks for reporting this, we will update this library as you suggested. We
also noticed it's used in :
* shell-dev-commands
* shell-commands
So we will update it everywhere it's used.
Regards,
Serge...
> Unomi uses a non OSS version of org.json:json jar
> -------------------------------------------------
>
> Key: UNOMI-821
> URL: https://issues.apache.org/jira/browse/UNOMI-821
> Project: Apache Unomi
> Issue Type: Bug
> Reporter: PJ Fanning
> Priority: Major
>
> See
> https://github.com/apache/unomi/blob/110286ad74ecaec927f3b61c54140d852dfbd4fe/extensions/unomi-mailchimp/services/pom.xml#L60
> Please read https://www.apache.org/legal/resolved.html (JSON license section).
> Newer version of this jar (2023/2024) have a Public Domain license so are ok.
> These releases have CVE fixes too.
--
This message was sent by Atlassian Jira
(v8.20.10#820010)