[ 
https://issues.apache.org/jira/browse/CONFIGURATION-776?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=18066528#comment-18066528
 ] 

Lenny Primak commented on CONFIGURATION-776:
--------------------------------------------

Please bump. I found the vulnerability reports:

[https://guide.sonatype.com/vulnerability/sonatype-2024-3350]

Also reflected here: https://issues.apache.org/jira/browse/COLLECTIONS-701

> Update Commons BeanUtils from 1.9. to 2.X
> -----------------------------------------
>
>                 Key: CONFIGURATION-776
>                 URL: https://issues.apache.org/jira/browse/CONFIGURATION-776
>             Project: Commons Configuration
>          Issue Type: Task
>    Affects Versions: 2.6
>            Reporter: Melloware
>            Priority: Major
>          Time Spent: 10m
>  Remaining Estimate: 0h
>
> Update Apache Commons BeanUtils from 1.9. to 2.X
> BeanUtils 2.X removes its dependency on Commons Collections but does change 
> package name to the beanutils2 package.



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to