Uploaded image for project: 'Quarkus'
  1. Quarkus
  2. QUARKUS-2455

[Docs]: 2.7 release notes link to internal JIRAS

XMLWordPrintable

      The Fixes section of the Red Hat build of Quarkus 2.7 release notes includes links to internal JIRAs. 

      8.1. Security fixes

      8.1.1. Quarkus 2.7.6

      • QUARKUS-2076 CVE-2021-3520 LZ4: memory corruption due to an integer overflow bug caused by the memmove argument
      • QUARKUS-1969 CVE-2020-36518 Jackson-databind: denial of service caused by a large depth of nested objects

       

              mpurcell@redhat.com Michelle Purcell
              mpurcell@redhat.com Michelle Purcell
              Votes:
              0 Vote for this issue
              Watchers:
              4 Start watching this issue

                Created:
                Updated:
                Resolved: