diff --git a/api/build.gradle b/api/build.gradle index 343ab3248..62e45480d 100644 --- a/api/build.gradle +++ b/api/build.gradle @@ -15,7 +15,7 @@ dependencies { implementation project(":serde-api") implementation libs.spring.starter.webflux implementation(libs.spring.starter.security){ - exclude group: 'com.nimbusds', module: 'nimbus-jose-jwt' because("Temporary overwrite to fix CVE-2025-5386. See https://avd.aquasec.com/nvd/2025/cve-2025-53864/") + exclude group: 'com.nimbusds', module: 'nimbus-jose-jwt' because("Temporary overwrite to fix CVE-2025-53864. See https://avd.aquasec.com/nvd/2025/cve-2025-53864/") } implementation(libs.nimbus.jose.jwt){ because("Fixes CVE-2025-5386. See https://avd.aquasec.com/nvd/2025/cve-2025-53864/") diff --git a/gradle/libs.versions.toml b/gradle/libs.versions.toml index 4636c2cd9..0a3d77098 100644 --- a/gradle/libs.versions.toml +++ b/gradle/libs.versions.toml @@ -61,7 +61,7 @@ spring-starter-actuator = { module = 'org.springframework.boot:spring-boot-start spring-starter-test = { module = 'org.springframework.boot:spring-boot-starter-test', version.ref = 'spring-boot' } spring-starter-webflux = { module = 'org.springframework.boot:spring-boot-starter-webflux', version.ref = 'spring-boot' } spring-starter-security = { module = 'org.springframework.boot:spring-boot-starter-security', version.ref = 'spring-boot' } -# Temporary overwrite to fix CVE-2025-5386 +# Temporary overwrite to fix CVE-2025-53864 nimbus-jose-jwt = { module = 'com.nimbusds:nimbus-jose-jwt', version.ref = 'nimbus-jose-jwt' } spring-starter-validation = { module = 'org.springframework.boot:spring-boot-starter-validation', version.ref = 'spring-boot' } spring-starter-oauth2-client = { module = 'org.springframework.boot:spring-boot-starter-oauth2-client', version.ref = 'spring-boot' }