关键信息 Jira Issue: AMQ-7279 Project: ActiveMQ Issue Type: Bug Affects Versions: 5.15.9 漏洞描述(摘录) jackson-databind-2.9.8.jar - Severity: SEV-2 - Description: FasterXML contains a flaw in jackson-databind, jso... - New Version: 2.9.9 tomcat-servlet-api-8.0.53.jar - Severity: SEV-3 - Description: Apache Tomcat 7.x through 7.0.70 and 8.x throug... - New Version: 9.0.22 - CVE: CVE-2016-5388 tomcat-websocket-api-8.0.53.jar - Severity: SEV-4 - Description: Apache Tomcat contains a flaw that is due to th... - New Version: 9.0.22 zookeeper-3.4.6.jar - Severity: SEV-4 - Description: Two four letter word commands "wcp/wch" are CPU... - New Version: 3.5.5 - CVE: CVE-2017-5637 guava-18.0.jar - Severity: SEV-4 - Description: Unbounded memory allocation in Google Guava 11.0... - New Version: 28.0 - CVE: CVE-2018-10237 jetty-all-9.2.26.v20180806.jar - Severity: SEV-4 - Description: In Eclipse Jetty, versions 9.2.x and older, 9.3... - New Version: 9.4.x - CVE: CVE-2017-7655