Details
-
Dependency upgrade
-
Status: Resolved
-
Major
-
Resolution: Fixed
-
9.0.0.RC1
-
None
Description
December 13, 2022 - Apache CXF 3.5.5 and 3.4.10 released!
The Apache CXF team is proud to announce the availability of our latest patch releases! Over 9 JIRA issues were fixed for 3.5.5 and 3.4.10. Two new CVEs were issued for vulnerabilities fixed in these releases:
CVE-2022-46363: Apache CXF directory listing / code exfiltration
CVE-2022-46364: Apache CXF SSRF Vulnerability
Attachments
Issue Links
- is related to
-
TOMEE-4125 Update Apache CXF versions to mitigate CVE-2022-46364 and CVE-2022-46363
- Resolved
- links to