Uploaded image for project: 'Quarkus'
  1. Quarkus
  2. QUARKUS-2455

[Docs]: 2.7 release notes link to internal JIRAS

XMLWordPrintable

    • Icon: Bug Bug
    • Resolution: Done
    • Icon: Major Major
    • 2.7.6.SP1.GA
    • 2.7.6.GA
    • team/docs
    • None

      The Fixes section of the Red Hat build of Quarkus 2.7 release notes includes links to internal JIRAs. 

      8.1. Security fixes

      8.1.1. Quarkus 2.7.6

      • QUARKUS-2076 CVE-2021-3520 LZ4: memory corruption due to an integer overflow bug caused by the memmove argument
      • QUARKUS-1969 CVE-2020-36518 Jackson-databind: denial of service caused by a large depth of nested objects

       

              mpurcell@redhat.com Michelle Purcell
              mpurcell@redhat.com Michelle Purcell
              Votes:
              0 Vote for this issue
              Watchers:
              4 Start watching this issue

                Created:
                Updated:
                Resolved: