From f12f4405c49fb572b1b0f003c68a627b04fbd887 Mon Sep 17 00:00:00 2001 From: lukasz-wolski <1005015+lukasz-wolski@users.noreply.github.com> Date: Wed, 29 Mar 2023 09:54:49 +0100 Subject: [PATCH] Nightly build failure Addresses CVE-2023-28708 Remedied in Tomcat 9.0.72 - https://tomcat.apache.org/security-9.html#Fixed_in_Apache_Tomcat_9.0.72 CVE found in https://static-build.platform.hmcts.net/static-files/WY9YElWyRTMnNXrF0JpKKVEESSPkgBJYx3ELIsaEsvQxNjgwMDc5NDM5NjI5OjI0Okx1a2Fzei5Xb2xza2kxQEhNQ1RTLk5FVDp2aWV3L1JEL2pvYi9ITUNUU19qX3RvX3pfTmlnaHRseS9qb2IvcmQtY2FzZXdvcmtlci1yZWYtYXBpL2pvYi9tYXN0ZXIvNDI5L2FydGlmYWN0/build/reports/dependency-check-report.html --- build.gradle | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/build.gradle b/build.gradle index 75aa9098e..c00d1611a 100644 --- a/build.gradle +++ b/build.gradle @@ -519,7 +519,7 @@ dependencyManagement { dependencies { // CVE-2021-42340 - dependencySet(group: 'org.apache.tomcat.embed', version: '9.0.71') { + dependencySet(group: 'org.apache.tomcat.embed', version: '9.0.72') { entry 'tomcat-embed-core' entry 'tomcat-embed-el' entry 'tomcat-embed-websocket'