Details
-
Bug
-
Status: Open
-
Major
-
Resolution: Unresolved
-
2.3.1
-
None
Description
WSS4J has a transitive dependency on velocity 1.7 (via OpenSAML 3.x) which is subject to a high security vulnerability ( https://nvd.nist.gov/vuln/detail/CVE-2020-13936 )
WSS4J should update its OpenSAML dependency to 4.x thereby allowing velocity-core-engine to be updated to the patched version (2.3)
Attachments
Attachments
Issue Links
- relates to
-
CXF-8621 cxf-rt-ws-security contains velocity:1.7 from 2010 which has overlapping classes with velocity-engine-core:2.3 and breaks velocity-tools 3.1
- Closed