Details
-
Bug
-
Status: Open
-
Major
-
Resolution: Unresolved
-
None
-
None
-
None
Description
The last release of org.apache.felix.webconsole.plugins.scriptconsole is 1.0.2 from 2015 which still uses org.json (version 2007) with many CVEs. It doesn't run with a recent org.json version, because the constructor argument of JSONWriter was changed long ago.
As far as I can see, the org.json dependency has been removed in version 1.0.3-SNAPSHOT, but there is no official 1.0.3 release.
Please release a version without org.json dependency.