Skip to content

Conversation

gaetan-deltombe
Copy link

Update dependencies:
from org.bouncycastle.bcpkix.jdk15on:1.70
to org.bouncycastle.bcpkix.jdk18on:1.78.1

from org.bouncycastle.bcprov.jdk15on:1.70
to org.bouncycastle.bcprov.jdk18on:1.78.1

Closes gh-15780

Spring security 6.1 is in Enterprise support but we do need to update the dependency of org.bouncycastle.bcpkix.jdk15on to org.bouncycastle.bcpkix.jdk18on in order to be able to fix the GHSA-8xfc-gm6g-vgpv and GHSA-4h8f-2wvx-gg5w.

CVEs revealed by OWASP.

see : https://nvd.nist.gov/vuln/detail/CVE-2024-29857 and https://nvd.nist.gov/vuln/detail/CVE-2024-34447

Update dependencies:
 from org.bouncycastle.bcpkix.jdk15on:1.70
 to org.bouncycastle.bcpkix.jdk18on:1.78.1

 from org.bouncycastle.bcprov.jdk15on:1.70
 to   org.bouncycastle.bcprov.jdk18on:1.78.1

 Closes spring-projectsgh-15780
@pivotal-cla
Copy link

@gaetan-deltombe Please sign the Contributor License Agreement!

Click here to manually synchronize the status of this Pull Request.

See the FAQ for frequently asked questions.

@pivotal-cla
Copy link

@gaetan-deltombe Thank you for signing the Contributor License Agreement!

@spring-projects-issues spring-projects-issues added the status: waiting-for-triage An issue we've not yet triaged label Sep 10, 2024
@gaetan-deltombe
Copy link
Author

I close this PR. The proposed solution is not complete.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

status: waiting-for-triage An issue we've not yet triaged

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants