Skip to content

[Backport] update dependencies to address CVEs#16395

Merged
kfaraz merged 1 commit intoapache:30.0.0from
adarshsanjeev:backport-16374-to-30.0.0
May 7, 2024
Merged

[Backport] update dependencies to address CVEs#16395
kfaraz merged 1 commit intoapache:30.0.0from
adarshsanjeev:backport-16374-to-30.0.0

Conversation

@adarshsanjeev
Copy link
Contributor

Backport of #16374 to 30.0.0.

update dependencies to address new batch of CVEs:
- Azure POM from 1.2.19 to 1.2.23 to update transitive dependency nimbus-jose-jwt to address:  CVE-2023-52428
- commons-configuration2 from 2.8.0 to 2.10.1 to address: CVE-2024-29131 CVE-2024-29133
- bcpkix-jdk18on from 1.76 to 1.78.1 to address: CVE-2024-30172 CVE-2024-30171 CVE-2024-29857
@adarshsanjeev adarshsanjeev added this to the 30.0.0 milestone May 6, 2024
@kfaraz kfaraz merged commit b26394e into apache:30.0.0 May 7, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants