Skip to content

Commit e47be24

Browse files
authored
[BlackDuck] Fix CVE-2024-7254 (#873)
1 parent 08f2777 commit e47be24

File tree

2 files changed

+7
-5
lines changed

2 files changed

+7
-5
lines changed

cloudplatform/connectivity-ztis/pom.xml

Lines changed: 0 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -31,11 +31,6 @@
3131
<dependencyManagement>
3232
<dependencies>
3333
<!-- resolve inconsistent versions coming from spiffe -> io.grpc -->
34-
<dependency>
35-
<groupId>com.google.protobuf</groupId>
36-
<artifactId>protobuf-java</artifactId>
37-
<version>3.25.8</version>
38-
</dependency>
3934
<dependency>
4035
<groupId>io.grpc</groupId>
4136
<artifactId>grpc-bom</artifactId>

pom.xml

Lines changed: 7 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -122,6 +122,7 @@
122122
<commons-codec.version>1.18.0</commons-codec.version>
123123
<commons-beanutils.version>1.11.0</commons-beanutils.version>
124124
<findbugs-jsr305.version>3.0.2</findbugs-jsr305.version>
125+
<protobuf-java.version>3.25.8</protobuf-java.version>
125126
<jsr305.optional>true</jsr305.optional>
126127
<maven-compiler-plugin.version>3.14.0</maven-compiler-plugin.version>
127128
<maven.compiler.proc>full</maven.compiler.proc>
@@ -296,6 +297,12 @@
296297
<artifactId>commons-beanutils</artifactId>
297298
<version>${commons-beanutils.version}</version>
298299
</dependency>
300+
<!-- resolve vulnerability CVE-2024-7254 -->
301+
<dependency>
302+
<groupId>com.google.protobuf</groupId>
303+
<artifactId>protobuf-java</artifactId>
304+
<version>${protobuf-java.version}</version>
305+
</dependency>
299306
<!--Dependencies with test scope-->
300307
<dependency>
301308
<groupId>com.sap.cloud.sdk</groupId>

0 commit comments

Comments
 (0)