We are currently using 3.3.0 which has a dependency on jersey-json-1.9 which in turn uses jackson-xc-1.9.x and jackson-jaxrs-1.9.x. These jackson-xc-1.9.x and jackson-jaxrs-1.9.x has a known security vulnerabilities reported in CVE-2018-14718 and CVE-2018-7489. The latest version (3.11.3) seem no longer using jersey-json-1.9.
We are currently using 3.3.0 which has a dependency on
jersey-json-1.9which in turn usesjackson-xc-1.9.xandjackson-jaxrs-1.9.x. Thesejackson-xc-1.9.xandjackson-jaxrs-1.9.xhas a known security vulnerabilities reported in CVE-2018-14718 and CVE-2018-7489. The latest version (3.11.3) seem no longer usingjersey-json-1.9.