projectodd / wunderboss

The next-generation polyglot platform for TorqueBox and Immutant
Apache License 2.0
17 stars 11 forks source link

Critical vulnerability in the latest stable release 0.13.1 #19

Open gavinkflam opened 6 years ago

gavinkflam commented 6 years ago

Description

There is a critical (9.8) severity vulnerability in the latest stable release of wunderboss-core.

Expected Behavior

I propose upgrading logback-classic to 1.2.3 and publish a stable release as soon as possible.

Actual Behavior

The vulnerabilities are affecting the latest stable release 0.5.3.

WunderBoss version

0.13.1