[ https://issues.apache.org/jira/browse/CXF-8157?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ]
Colm O hEigeartaigh closed CXF-8157. ------------------------------------ > Update to Jackson Databind 2.9.10.1 > ----------------------------------- > > Key: CXF-8157 > URL: https://issues.apache.org/jira/browse/CXF-8157 > Project: CXF > Issue Type: Task > Affects Versions: 3.3.4 > Reporter: Andriy Redko > Assignee: Andriy Redko > Priority: Major > Fix For: 3.4.0, 3.3.5 > > Time Spent: 20m > Remaining Estimate: 0h > > 2.9.10.1 (20-Oct-2019) > #2478: Block two more gadget types (commons-dbcp, p6spy, CVE-2019-16942 / > CVE-2019-16943) (reported by b5mali4 / r...@codersec.net) > #2498: Block one more gadget type (log4j-extras/1.2, CVE-2019-17531) -- This message was sent by Atlassian Jira (v8.3.4#803005)