Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Critical Security Severity on 4.9.4 #1767

Closed
Boldbayar opened this issue Aug 19, 2022 · 2 comments
Closed

Critical Security Severity on 4.9.4 #1767

Boldbayar opened this issue Aug 19, 2022 · 2 comments
Labels
needs-review issue/PR needs review from maintainer

Comments

@Boldbayar
Copy link

Hello, I have found the following security issue by scanning with snyk

Provides transitive vulnerable dependency org.bouncycastle:bcprov-jdk15on:1.68

  1. https://advisory.checkmarx.net/advisory/vulnerability/Cxa9261daf-3755/ on dependency
@Boldbayar Boldbayar added the needs-review issue/PR needs review from maintainer label Aug 19, 2022
@jjanczur
Copy link

I see it as well. You can probably fix it by forcing maven/Gradle to use a higher version of the bouncy castle in properties (similarly to upgrading log4j lib - CVE-2021-45105 ) but I don't know if it won't break the library/tests.

@mohamedelshami mohamedelshami pinned this issue Oct 20, 2022
@mohamedelshami
Copy link
Contributor

@Boldbayar thank you for this finding, we will look into possibly adding a dependency override.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
needs-review issue/PR needs review from maintainer
Projects
None yet
Development

No branches or pull requests

3 participants