Closed
Description
Compiler version
The issue exists in both versions 3.1.1-RC2
and 3.1.2-DEV
of the Scala 3 software distribution.
Affected Java library
Both Java libraries jackson-databind 2.2.x
and liqp 0.6.x
are affected by over 40 CVE and
- Dependency on
jackson-databind
2.2.3
exists in all Scala 3 distributions since version 3.0.0. - Dependency on
liqp
0.6.7
exists in versions 3.0.x up to 3.1.1-RC2. - Dependency on
liqp
0.6.8
exists in version 3.1.2-DEV.
Final Notes
- In January 2018 @smarter failed to update
liqp
as described in issue 3859 and I did not find any trace of another try. - In October 2021 @michelou opened discussion17799 to gain attention but without success to date.
CC @sjrd @SethTisue