Details
-
Fix
-
Status: Released (View Workflow)
-
Minor
-
Resolution: Fixed
-
1.12, 1.13
-
None
-
CVE-2020-13933
Description
Current Situation
- Currently JobScheduler components use org.apache.shiro:shiro-core version 1.5.0
- a vulnerability affects this version,
Desired Behavior
- Due to a vulnerability Issue of older org.apache.shiro:shiro-core releases the JobScheduler components should use the current version 1.71 that fixes the issues.