Re: Bug#700610: bsh (BeanShell) security vulnerability (CVE-2016-2510)

2022-02-22 Thread Thorsten Glaser
On Tue, 22 Feb 2022, Thomas Uhle wrote: > What do you think, wouldn't it be time for an update in Debian? The comment > at https://github.com/beanshell/beanshell/issues/603 . reads for me more like a “maybe remove it instead…”. Honestly though, if it’s not available in Central, upstreams will no

Re: Bug#700610: bsh (BeanShell) security vulnerability (CVE-2016-2510)

2022-02-22 Thread Thomas Uhle
Dear maintainers, there was published a new release of BeanShell 14 months ago. You can find the sources of version 2.1.0 on GitHub at https://github.com/beanshell/beanshell/releases/tag/2.1.0 The new version has not been published on Maven though (where versions from 2.0b4 to 2.0b6 are stil