qubole/qds-sdk-java

support for jersey 2.22.X

Opened this issue · 2 comments

The project is using older versions of jersey libraries. It's about time they are upgraded.

Hi @vivekkothari,

Thanks for reporting this. jersey >= v2.7 requires Java 7. We don't want to drop support for Java 6 yet.

any word on this? not being on a higher version of jersey (I think >= 2.9) means this project is susceptible to https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-7489