Hi Kostas,
The answer to your second question is "most likely not", but it is often
simpler to just upgrade the libraries than to figure out exactly what the
vulnerability is, and why it can't be exploited the way the library is used.
We regularly upgrade libraries, so we'll review the CVEs you mentioned, and
upgrade the relevant libraries if necessary. We generally put those changes
in point releases for Orbeon Forms PE, but you'll most likely have to wait
for the 2019.1 release to get this in an official Orbeon Forms CE release.
‑Alex
-----
--
Follow Orbeon on Twitter: @orbeon
Follow me on Twitter: @avernet
--
Sent from:
http://discuss.orbeon.com/--
You received this message because you are subscribed to the Google Groups "Orbeon Forms" group.
To unsubscribe from this group and stop receiving emails from it, send an email to
[hidden email].
To post to this group, send email to
[hidden email].
--
Follow Orbeon on Twitter: @orbeon
Follow me on Twitter: @avernet