Jar file version 1.0.1 contains not used package 'org.apache.commons.collections.*'
Opened this issue · 1 comments
toutzhang commented
Version 1.0.1 jar file contains package 'org.apache.commons.collections.*', which was not used anymore. Please remove it in future release.
toutzhang commented
What's more, commons-beanutils can be update to 1.9.4.
FYI, https://www.cvedetails.com/cve/CVE-2019-10086/