eclipse-ee4j / eclipse-ee4j/jersey
Remove vulnerable jersey-media-json-jackson1 from jersey BOM
Open
- Dominant language
- Java
- Stars
- 730
- Forks
- 382
- PR merge metrics
- No merged PRs in 30d
Description
The jersey-media-json-jackson1 is affected by CVE-2019-10202 and the patch is already available in jersey-media-json-jackson, since Jersey BOM has both of these dependencies it's better to remove the vulnerable one so that the users don't use them accidentally.
Contributor guide
Assessment
This issue has not been assessed yet.