Skip to content
New issue

Have a question about this project? # for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “#”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? # to your account

[fix][sec] Upgrade org.bouncycastle:bc-fips to 1.0.2.4 #21730

Merged
merged 1 commit into from
Dec 15, 2023

Conversation

massakam
Copy link
Contributor

@massakam massakam commented Dec 15, 2023

Motivation

The currently used version of org.bouncycastle:bc-fips has the following vulnerability and should be upgraded to 1.0.2.4.
https://github.com/bcgit/bc-java/wiki/CVE-2022-45146

https://nvd.nist.gov/vuln/detail/CVE-2022-45146

Verifying this change

  • Make sure that the change passes the CI checks.

Documentation

  • doc
  • doc-required
  • doc-not-needed
  • doc-complete

@massakam massakam added type/bug The PR fixed a bug or issue reported a bug area/security doc-not-needed Your PR changes do not impact docs ready-to-test labels Dec 15, 2023
@massakam massakam added this to the 3.2.0 milestone Dec 15, 2023
@massakam massakam self-assigned this Dec 15, 2023
@merlimat merlimat merged commit 60522c6 into apache:master Dec 15, 2023
53 of 57 checks passed
@massakam massakam deleted the bump-bc-fips branch December 18, 2023 01:49
nikhil-ctds pushed a commit to datastax/pulsar that referenced this pull request Dec 20, 2023
srinath-ctds pushed a commit to datastax/pulsar that referenced this pull request Dec 20, 2023
# for free to join this conversation on GitHub. Already have an account? # to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants