JLine 4.4.3 is a security patch release addressing multiple vulnerabilities reported by AFINE/CERT.PL, plus bug fixes and dependency updates.
馃敀 Security Fixes
- Native Stack Buffer Overflow in Public INPUT_RECORD.memmove JNI Method (Windows) (GHSA-6r3w-6jpj-x5w6)
- Authenticated SSH Shell Channel Resource Leak via Null or Non-Numeric PTY Dimensions (GHSA-7h86-pjwh-gpqj)
- Authenticated SSH DoS via Unbounded Window-Change Terminal Geometry (GHSA-m935-wqpj-pvp3)
- TCP Socket File Descriptor Leak When Maximum Connections Reached (GHSA-c87g-867h-cqr6)
馃悰 Bug Fixes
- fix: verify server host keys in the ssh client builtin (#2236) @uchiha-bug-hunter
- fix: address remaining security vulnerabilities reported by AFINE/CERT.PL (#2235) @gnodet
- fix: use Release Drafter draft for GitHub release and fail closed on lookup errors (#2232) @gnodet
馃摝 Dependency updates
- chore: bump org.graalvm.buildtools:native-maven-plugin from 1.1.11 to 1.1.12 (#2242) @dependabot[bot]
- chore: bump com.diffplug.spotless:spotless-maven-plugin from 3.10.1 to 3.10.2 (#2246) @dependabot[bot]
- chore: bump groovy.version from 5.1.1 to 5.1.2 (#2245) @dependabot[bot]
- chore: bump slf4j.version from 2.0.18 to 2.0.19 (#2244) @dependabot[bot]
- chore: bump org.apache.maven.plugins:maven-surefire-plugin from 3.5.6 to 3.6.0 (#2234) @dependabot[bot]