Skip to content

Conversation

sgrampone
Copy link
Contributor

Issue:101616
Bump library esapi-2-0-1 to essapi-2.3.0.0, it is a dependency of opensaml library and it does not have an update available. We are trying to overwrite its dependency.
CVE-2022-23457
CVE-2022-24891
CVE-2013-5960
CVE-2013-5679
#GXSEC

@sgrampone sgrampone added the dependencies Pull requests that update a dependency file label Mar 24, 2023
@sgrampone sgrampone requested a review from iroqueta March 24, 2023 18:45
@genexusbot
Copy link
Collaborator

Cherry pick to beta success

@genexusbot
Copy link
Collaborator

Cherry pick to beta success

@genexusbot
Copy link
Collaborator

Cherry pick to beta success

…c library.

It's ok to use the dependency version that needs ws4j
Issue:101616
@genexusbot
Copy link
Collaborator

Cherry pick to beta success

@iroqueta iroqueta merged commit e467e94 into master Apr 5, 2023
@iroqueta iroqueta deleted the issue#101616 branch April 5, 2023 21:24
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
bot closed dependencies Pull requests that update a dependency file
Projects
None yet
Development

Successfully merging this pull request may close these issues.

4 participants