-
Bug
-
Resolution: Done
-
Major
-
2.7.6.GA
-
None
-
1
-
False
-
None
-
False
-
?
-
---
The Fixes section of the Red Hat build of Quarkus 2.7 release notes includes links to internal JIRAs.
8.1.1. Quarkus 2.7.6
- QUARKUS-2076 CVE-2021-3520 LZ4: memory corruption due to an integer overflow bug caused by the memmove argument
- QUARKUS-1969 CVE-2020-36518 Jackson-databind: denial of service caused by a large depth of nested objects
- is cloned by
-
QUARKUS-2457 Enhance cryptic descriptions in 2.7 release notes
- Closed
-
QUARKUS-2458 Fix 2.7 release notes to use official CVE links and descriptions verbatim not JIRAS
- Closed
- relates to
-
QUARKUS-2458 Fix 2.7 release notes to use official CVE links and descriptions verbatim not JIRAS
- Closed
- mentioned on