Hello,

I see that the recommended approach to avoid exposure to the CVE-2020-13949 is upgrading to version 0.14.0. However this version brings some breaking changes and upgrading is bit challenging for some of our projects.

Has it been considered to backport the fixes into 0.13 stream?
Would it be too demanding to do?

Thanks for any statements on this!

Best regards,
--
Tomas Hofman
Software Engineer, JBoss SET
Red Hat

Reply via email to