Robert Schaft created CXF-8328:
----------------------------------
Summary: CVE-2019-12406 not fixed in 3.1 branch
Key: CXF-8328
URL: https://issues.apache.org/jira/browse/CXF-8328
Project: CXF
Issue Type: Bug
Components: Core
Affects Versions: 3.1.18
Reporter: Robert Schaft
CVE-2019-12406 is currently the only open relevant Cybersecurity issue in TomEE
7.x (see TOMEE-2876) according to known vulnerability database.
TomEE 7.x is claiming to be a stable supported version. But it depends on CXF
3.1, which has at least the vulnerability reported in
[CVE-2019-12406|http://cxf.apache.org/security-advisories.data/CVE-2019-12406.txt.asc].
As I understood, it can't be fixed in TomEE without following the API change of
CXF 3.2, which the TomEE team is reluctant to do.
>From the distant perspective, a backport to CXF 3.1 of theĀ
>attachment-max-count feature doesn't look complicated.
--
This message was sent by Atlassian Jira
(v8.3.4#803005)