Spring security 6.1 : CVE-2024-29857, CVE-2024-34447 org.bouncycastle.bcpkix.jdk15on:1.70 #15782
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Update dependencies:
from org.bouncycastle.bcpkix.jdk15on:1.70
to org.bouncycastle.bcpkix.jdk18on:1.78.1
from org.bouncycastle.bcprov.jdk15on:1.70
to org.bouncycastle.bcprov.jdk18on:1.78.1
Closes gh-15780
Spring security 6.1 is in Enterprise support but we do need to update the dependency of org.bouncycastle.bcpkix.jdk15on to org.bouncycastle.bcpkix.jdk18on in order to be able to fix the GHSA-8xfc-gm6g-vgpv and GHSA-4h8f-2wvx-gg5w.
CVEs revealed by OWASP.
see : https://nvd.nist.gov/vuln/detail/CVE-2024-29857 and https://nvd.nist.gov/vuln/detail/CVE-2024-34447