Skip to content

Update org.bitbucket.b_c:jose4j to 0.9.4 #217

New issue

Have a question about this project? # for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “#”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? # to your account

Open
wants to merge 2 commits into
base: master
Choose a base branch
from

Conversation

had1z
Copy link

@had1z had1z commented Feb 21, 2025

There are 2 vulnerabilities reported for org.bitbucket.b_c:jose4j 0.7.9

CVE-2023-31582:

  • Severity: High
  • Patched versions: 0.9.3

CVE-2023-51775:

  • Severity: Moderate
  • Patched versions: 0.9.4

This pull request updates org.bitbucket.b_c:jose4j to 0.9.4 to address those vulnerabilities.

@jmini
Copy link
Contributor

jmini commented Mar 6, 2025

I agree, you can even go to 0.9.6 as suggested in #192

@had1z
Copy link
Author

had1z commented Mar 13, 2025

Changed to 0.9.6 as you suggested.

# for free to join this conversation on GitHub. Already have an account? # to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants