[
https://issues.apache.org/jira/browse/CXF-8328?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17181336#comment-17181336
]
Robert Schaft commented on CXF-8328:
------------------------------------
Before closing this issue by principle, please think about the downstream effect
Won't fix Vulnerability in CXF 3.1 -> Unfixable Vulnerability in TomEE 7.1 ->
Unusable TomEE 7.1 in production -> Early end of life for TomEE 7.1
> CVE-2019-12406 not fixed in 3.1 branch
> --------------------------------------
>
> Key: CXF-8328
> URL: https://issues.apache.org/jira/browse/CXF-8328
> Project: CXF
> Issue Type: Bug
> Components: Core
> Affects Versions: 3.1.18
> Reporter: Robert Schaft
> Priority: Major
> Labels: CVE
>
> CVE-2019-12406 is currently the only open relevant Cybersecurity issue in
> TomEE 7.x (see TOMEE-2876) according to known vulnerability database.
> TomEE 7.x is claiming to be a stable supported version. But it depends on CXF
> 3.1, which has at least the vulnerability reported in
> [CVE-2019-12406|http://cxf.apache.org/security-advisories.data/CVE-2019-12406.txt.asc].
> As I understood, it can't be fixed in TomEE without following the API change
> of CXF 3.2, which the TomEE team is reluctant to do.
> From the distant perspective, a backport to CXF 3.1 of theĀ
> attachment-max-count feature doesn't look complicated.
--
This message was sent by Atlassian Jira
(v8.3.4#803005)