Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Upgrade Bouncy Castle to 1.78 or newer #594

Closed
barchetta opened this issue Apr 19, 2024 · 9 comments
Closed

Upgrade Bouncy Castle to 1.78 or newer #594

barchetta opened this issue Apr 19, 2024 · 9 comments
Labels
SDK Issue pertains to the SDK itself and not specific to any service

Comments

@barchetta
Copy link
Member

Please upgrade Bouncy Castle to 1.78 or newer

https://www.bouncycastle.org/releasenotes.html#r1rv78

@r0bertini
Copy link

There is high security issue based on the release notes to versions prior 1.78, so please prioritize this upgrade accordingly, thanks.

For details see CVE-2024-301XX on page https://www.bouncycastle.org/releasenotes.html#r1rv78

@jyotisaini
Copy link

jyotisaini commented Apr 29, 2024

Hi @robander - This is already prioritised and is in our roadmap to upgrade the bouncy castle. Please watch this issue for further updates.

@r0bertini
Copy link

Thanks @jyotisaini I assume there is no ETA which could be shared here?

@barchetta
Copy link
Member Author

Any status on this?

@jyotisaini
Copy link

ETA for the bouncy castle upgrade is 06/04.

@jyotisaini jyotisaini added the SDK Issue pertains to the SDK itself and not specific to any service label May 21, 2024
@r0bertini
Copy link

@jyotisaini was this released yesterday or is there a new timeline please ?

@jyotisaini
Copy link

Hi Robert this is scheduled to go out on 06/11.

@r0bertini
Copy link

Just confirming this has been released yesterday - v3.43.2 - see pom.xml file in v3.43.1...v3.43.2

@barchetta
Copy link
Member Author

Closing as this is fixed in v3.43.2

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
SDK Issue pertains to the SDK itself and not specific to any service
Projects
None yet
Development

No branches or pull requests

3 participants