Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Upgrade Versions - Fix Security Vulnerabilities #303

Merged
merged 3 commits into from
Jun 5, 2024
Merged

Upgrade Versions - Fix Security Vulnerabilities #303

merged 3 commits into from
Jun 5, 2024

Conversation

flamaral256
Copy link
Contributor

No description provided.

@ar
Copy link
Member

ar commented Jun 3, 2024

Please detail which security vulnerabilities this PR addresses.

@flamaral256
Copy link
Contributor Author

Vulnerabilities + upgrades in this pull request:

org.slf4j:slf4j-api
just upgrade version to last stable

ch.qos.logback:logback-classic
CVE-2023-6378

org.hibernate:hibernate-core
just upgrade version to last stable

org.eclipse.jetty:jetty-server
just upgrade version to last stable

com.google.guava:guava
CVE-2023-2976
CVE-2020-8908

org.jline:jline
Vulnerabilities from dependencies:
CVE-2023-35887

io.netty:netty-handler
CVE-2023-4586
CVE-2023-34462

mysql:mysql-connector-java
Vulnerabilities from dependencies:
CVE-2022-3510
CVE-2022-3509
CVE-2022-3171

com.mchange:c3p0
just upgrade version to last stable

org.postgresql:postgresql
CVE-2024-1597
CVE-2022-41946
CVE-2022-31197
CVE-2022-26520
CVE-2022-21724

org.flywaydb:flyway-core
Vulnerabilities from dependencies:
CVE-2024-1597
CVE-2022-41946
CVE-2022-31197
CVE-2022-26520
CVE-2022-21724
CVE-2020-13692

org.elasticsearch.client:elasticsearch-rest-high-level-client
Vulnerabilities from dependencies:
CVE-2024-23450
CVE-2023-46673
CVE-2023-31419
CVE-2023-31418
CVE-2023-31417
CVE-2022-23710
CVE-2022-23708

org.json:json
CVE-2023-5072
CVE-2022-45688

@ar ar merged commit b03d77b into jpos:master Jun 5, 2024
@flamaral256 flamaral256 deleted the patch-1 branch June 5, 2024 19:06
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants