Skip to content

Commit 1231e5e

Browse files
CCD-5159: (#151)
* CCD-5159: Fix CVE-2023-6378, upgrading logback-core and logback-classic from 1.2.10 to 1.5.6. Removed version.logback --------- Co-authored-by: shahirali <[email protected]>
1 parent 427e548 commit 1231e5e

File tree

2 files changed

+3
-2
lines changed

2 files changed

+3
-2
lines changed

build.gradle

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -193,6 +193,9 @@ dependencies {
193193

194194
implementation group: 'com.github.hmcts.java-logging', name: 'logging', version: '6.0.1'
195195

196+
implementation group: 'ch.qos.logback', name: 'logback-classic', version: '1.5.6'
197+
implementation group: 'ch.qos.logback', name: 'logback-core', version: '1.5.6'
198+
196199
implementation group: 'org.apache.logging.log4j', name: 'log4j-api', version: log4JVersion
197200
implementation group: 'org.apache.logging.log4j', name: 'log4j-to-slf4j', version: log4JVersion
198201
testImplementation group: 'io.rest-assured', name: 'rest-assured', version: '4.5.1'

config/owasp/suppressions.xml

Lines changed: 0 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -2,12 +2,10 @@
22
<suppress>
33
<notes>Temporary Suppression
44
CVE-2023-34055 refer [Ticket]
5-
CVE-2023-6378 refer [Ticket]
65
CVE-2023-35116 refer [Ticket]
76
CVE-2023-6481 refer [Ticket]
87
</notes>
98
<cve>CVE-2023-34055</cve>
10-
<cve>CVE-2023-6378</cve>
119
<cve>CVE-2023-35116</cve>
1210
<cve>CVE-2023-6481</cve>
1311
</suppress>

0 commit comments

Comments
 (0)