The updated packages fix several bugs and some security issues:
Side-channel attack risks in Elliptic Curve (EC) cryptography. (CVE-2019-2745)
Insufficient checks of suppressed exceptions in deserialization. (CVE-2019-2762)
Unbounded memory allocation during deserialization in Collections. (CVE-2019-2769)
Insufficient restriction of privileges in AccessController. (CVE-2019-2786)
Missing URL format validation. (CVE-2019-2816)
Missing array bounds check in crypto providers. (CVE-2019-2842)