Skip to content

Conversation

@julianladisch
Copy link
Contributor

See GHSA-3wfh-36rx-9537 "Timing Attack Vulnerability in SCRAM Authentication"

Motivation:

Upgrade the scram-client to fix a security vulnerability.

Conformance:

See GHSA-3wfh-36rx-9537 "Timing Attack Vulnerability in SCRAM Authentication"
Copy link
Contributor

@tsegismont tsegismont left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thank you @julianladisch !

Should be ok to upgrade, the release notes indicate the security fix is the only change in this release

https://github.com/ongres/scram/releases/tag/3.2

@tsegismont tsegismont merged commit 9d265eb into eclipse-vertx:master Sep 30, 2025
18 checks passed
@tsegismont tsegismont added this to the 5.1.0 milestone Sep 30, 2025
tsegismont added a commit that referenced this pull request Sep 30, 2025
tsegismont added a commit that referenced this pull request Sep 30, 2025
@julianladisch julianladisch deleted the scram-client-3.2 branch October 9, 2025 11:02
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants