You can try to override the dependency by dependency exclusion on
camel-cxf, but it's not a best practice.

We can eventually update on the LTS branch and release for 3.7.5

Il giorno mar 18 mag 2021 alle ore 11:34 Chio Chuan Ooi <chioch...@gmail.com>
ha scritto:

> Hi All,
>
> i am currently using camel 3.7.4 and notice that camel-cxf is using cxf
> 3.4.2.
> For cxf 3.4.2, notice there is a vulnerability in 3.4.2 and already fixed
> in cxf 3.4.3.
>
> when checking on jira CAMEL-16434
> <https://issues.apache.org/jira/browse/CAMEL-16434>, it seems that the cxf
> 3.4.3 is only done for camel 3.10
> so if i want to update to use cxf 3.4.3, is that possible?
>
>
> Thanks and Regards,
> Chio Chuan
>

Reply via email to