Skip to content

Conversation

@sgrampone
Copy link
Contributor

@sgrampone sgrampone commented Nov 20, 2025

Issue:207171

Bump odata libraries to version 5.0.0 (latest) and overwriting transitive vulnerable dependencies.

CVE-2025-52999
CVE-2022-42003
CVE-2022-42004
CVE-2020-36518
CVE-2024-47554
CVE-2025-48924

#GXSEC

@sgrampone sgrampone requested a review from iroqueta November 20, 2025 12:08
@sgrampone sgrampone added the dependencies Pull requests that update a dependency file label Nov 20, 2025
@genexusbot
Copy link
Collaborator

Cherry pick to beta failed, 1 conflicted file in commit d8909d0
  • pom.xml

1 similar comment
@genexusbot
Copy link
Collaborator

Cherry pick to beta failed, 1 conflicted file in commit d8909d0
  • pom.xml

@genexusbot
Copy link
Collaborator

Manual cherry pick to beta success

@sgrampone sgrampone merged commit ac3f700 into master Nov 25, 2025
10 checks passed
@sgrampone sgrampone deleted the fix/bump-odata-client-core branch November 25, 2025 13:30
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bot closed dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants