Robert Schaft created CXF-8328:
----------------------------------

             Summary: CVE-2019-12406 not fixed in 3.1 branch
                 Key: CXF-8328
                 URL: https://issues.apache.org/jira/browse/CXF-8328
             Project: CXF
          Issue Type: Bug
          Components: Core
    Affects Versions: 3.1.18
            Reporter: Robert Schaft


CVE-2019-12406 is currently the only open relevant Cybersecurity issue in TomEE 
7.x (see TOMEE-2876) according to known vulnerability database.

TomEE 7.x is claiming to be a stable supported version. But it depends on CXF 
3.1, which has at least the vulnerability reported in 
[CVE-2019-12406|http://cxf.apache.org/security-advisories.data/CVE-2019-12406.txt.asc].

As I understood, it can't be fixed in TomEE without following the API change of 
CXF 3.2, which the TomEE team is reluctant to do.

>From the distant perspective, a backport to CXF 3.1 of theĀ 
>attachment-max-count feature doesn't look complicated.



--
This message was sent by Atlassian Jira
(v8.3.4#803005)

Reply via email to