Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Upgrade OWASP java-html-sanitizer to avoid Guava vulnerability warnings #28385

Closed
casewalker opened this issue Apr 3, 2024 · 0 comments · Fixed by #28386
Closed

Upgrade OWASP java-html-sanitizer to avoid Guava vulnerability warnings #28385

casewalker opened this issue Apr 3, 2024 · 0 comments · Fixed by #28386

Comments

@casewalker
Copy link
Contributor

casewalker commented Apr 3, 2024

Description

Currently, the owasp-java-html-sanitizer dependency is at version 20220608.1, but this version pulls in Guava at version 30.1-jre, which leads to security warnings CVE-2023-2976 and CVE-2020-8908. These likely do not affect Keycloak, but they are a distraction which could obfuscate more real security issues worth looking in to.

The owasp-java-html-sanitizer recently released version 20240325.1 which completely removes Guava, thus removing the above CVEs too.

Keycloak should upgrade the owasp-java-html-sanitizer.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging a pull request may close this issue.

1 participant