You can try to override the dependency by dependency exclusion on camel-cxf, but it's not a best practice.
We can eventually update on the LTS branch and release for 3.7.5 Il giorno mar 18 mag 2021 alle ore 11:34 Chio Chuan Ooi <chioch...@gmail.com> ha scritto: > Hi All, > > i am currently using camel 3.7.4 and notice that camel-cxf is using cxf > 3.4.2. > For cxf 3.4.2, notice there is a vulnerability in 3.4.2 and already fixed > in cxf 3.4.3. > > when checking on jira CAMEL-16434 > <https://issues.apache.org/jira/browse/CAMEL-16434>, it seems that the cxf > 3.4.3 is only done for camel 3.10 > so if i want to update to use cxf 3.4.3, is that possible? > > > Thanks and Regards, > Chio Chuan >