[
https://issues.apache.org/jira/browse/KARAF-7365?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
]
Jean-Baptiste Onofré resolved KARAF-7365.
-----------------------------------------
Fix Version/s: (was: 4.4.0)
(was: 4.3.7)
Resolution: Duplicate
> Upgrade sling-commons-johnzon to 1.2.14
> ---------------------------------------
>
> Key: KARAF-7365
> URL: https://issues.apache.org/jira/browse/KARAF-7365
> Project: Karaf
> Issue Type: Task
> Components: karaf
> Affects Versions: 4.3.6
> Reporter: Karthick
> Assignee: Jean-Baptiste Onofré
> Priority: Major
>
> Security scans on our software that uses Apache Karaf 4.3.6 showed
> CVE-2016-0956 related to Apache Sling commons johnzon
>
> This latest version of Karaf uses 1.2.6 version of sling while the latest
> available is 1.2.14. So please plan to update the 3pp so as to not miss the
> recent software and security updates
>
>
>
--
This message was sent by Atlassian Jira
(v8.20.1#820001)