-
-
Notifications
You must be signed in to change notification settings - Fork 1.8k
Closed
Labels
Description
Module
MySQL
Testcontainers version
1.21.3
Using the latest Testcontainers version?
Yes
Host OS
MacOS
Host Arch
ARM
Docker version
Client:
Version: 28.4.0
API version: 1.51
Go version: go1.24.7
Git commit: d8eb465
Built: Wed Sep 3 20:56:26 2025
OS/Arch: darwin/arm64
Context: desktop-linux
Server: Docker Desktop 4.47.0 (206054)
Engine:
Version: 28.4.0
API version: 1.51 (minimum version 1.24)
Go version: go1.24.7
Git commit: 249d679
Built: Wed Sep 3 20:58:53 2025
OS/Arch: linux/arm64
Experimental: false
containerd:
Version: 1.7.27
GitCommit: 05044ec0a9a75232cad458027ca83437aae3f4da
runc:
Version: 1.2.5
GitCommit: v1.2.5-0-g59923ef
docker-init:
Version: 0.19.0
GitCommit: de40ad0
What happened?
Summary
This PR upgrades the MySQL JDBC driver dependency from mysql:mysql-connector-java:8.0.33 to com.mysql:mysql-connector-j:8.2.0 to address critical security vulnerabilities.
Security Vulnerabilities Fixed
CVE-2023-22102 (High Severity - CVSS 8.3)
- Component: MySQL Connector/J
- Affected Versions: 8.0.33, 8.1.0 and prior
- Issue: Access Control Bypass vulnerability in the MySQL Connectors product
- Fix: Upgrade to version 8.2.0 or higher
- References:
Changes Made
Dependency Updates
Updated MySQL JDBC driver in the following files:
modules/jdbc-test/build.gradlemodules/junit-jupiter/build.gradlemodules/spock/build.gradlemodules/oceanbase/build.gradlemodules/tidb/build.gradledocs/examples/junit4/generic/build.gradle
Additional Information
PR link :- #11078