Skip to content

Update dependency org.springframework.vault:spring-vault-core to v2.3.3 [SECURITY]#27

Open
renovate[bot] wants to merge 1 commit intomasterfrom
renovate/maven-org.springframework.vault-spring-vault-core-vulnerability
Open

Update dependency org.springframework.vault:spring-vault-core to v2.3.3 [SECURITY]#27
renovate[bot] wants to merge 1 commit intomasterfrom
renovate/maven-org.springframework.vault-spring-vault-core-vulnerability

Conversation

@renovate
Copy link

@renovate renovate bot commented May 23, 2024

This PR contains the following updates:

Package Change Age Confidence
org.springframework.vault:spring-vault-core (source) 2.3.22.3.3 age confidence

GitHub Vulnerability Alerts

CVE-2023-20859

In Spring Vault, versions 3.0.x prior to 3.0.2 and versions 2.3.x prior to 2.3.3 and older versions, an application is vulnerable to insertion of sensitive information into a log file when it attempts to revoke a Vault batch token.


Release Notes

spring-projects/spring-vault (org.springframework.vault:spring-vault-core)

v2.3.3

Compare Source

📗 Links

⭐ New Features

  • Refine logging after token revocation failure #​766
  • Allow reuse of library-specific configuration code in ClientHttpRequestFactoryFactory and ClientHttpConnectorFactory #​760
  • Azure MSI auth to use with reactive infra #​665
  • Enable system-property-driven proxy configuration for Reactor Netty's HTTP Client #​654
  • Keystore's certificate chain derived from Vault issue-certificate lacks CA authority certificate #​648
  • LifecycleAwareSessionManager doesn't differentiate between failed token renewals and intermittent network exceptions #​646
  • Bumped Azure IMDS API version #​644

🐞 Bug Fixes

  • Do not revoke batch tokens #​764
  • VaultException thrown without "cause" hides important information #​713
  • Fix typos in GCP IAM builders #​657
  • AppRole authentication failed when only providing roleId using AuthenticationSteps #​656
  • Fix assertion message #​649

📔 Documentation

🔨 Dependency Upgrades

  • Upgrade to Project Reactor 2020.0.30 #​773
  • Upgrade to Spring Data 2020.0.15 #​772
  • Upgrade to Spring Framework 5.3.26 #​771
  • Increase netty version to address security vulnerabilities #​670

❤️ Contributors

We'd like to thank all the contributors who worked on this release!


Configuration

📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Enabled.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants