[🍒][PLUGIN-1918] [PLUGIN-1904] [PLUGIN-1907] Fix: Vulnerability issues due to commons-lang3, org.json and logback-classic #330
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
[🍒]
🍒 [cherrypick]
Commits:
PR:
JIRA:
Description:
PLUGIN-1918: This PR upgrades the version of
commons-lang3library fromv3.8.1tov3.18.0thereby fixing the vulnerability: CVE-2025-48924 present in the older version.PLUGIN-1904: This PR upgrades the version of
org.jsonlibrary fromv20180813tov20231013along with minimal code changes for handling the value conversion from BigDecimal type to double type, thereby fixing the vulnerabilities: CVE-2022-45688 and CVE-2023-5072 present in the older version.PLUGIN-1907: This PR upgrades the version of
logback-classiclibrary fromv1.2.8tov1.2.13thereby fixing the vulnerability: CVE-2023-6378 present in the older version.