-
-
Notifications
You must be signed in to change notification settings - Fork 1.4k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Block two more gadget types (commons-configuration/-2) #2462
Comments
This comment has been minimized.
This comment has been minimized.
Since you mentioned commons config 1.9 you might also want to block
|
This comment has been minimized.
This comment has been minimized.
I'd prefer a proof-of-concept showing how these could be used: I agree there is potential, but something to indicate actual mechanism (but if so, send email via fasterxml.com). |
I agree what you said. Besides, I wonder to know if 2.9.10 version would be released in mid-October or later? |
I have send a email to [email protected]. The article is written in Chinese, published in a china security community |
I hope 2.9.10 can released early in October, in first part. I just want to wait for 2.10.0 to get out first. |
Ok, so, I filed Xalan part under #2469 |
|
Another gadget (*) type report regarding a class of
commons-configuration
(and latercommons-configuration2
) package(s)Mitre id: not yet allocated
Reporter: @ybhou1993
Fixed in:
(*) See https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062 for more on general problem type
The text was updated successfully, but these errors were encountered: