Done
Details
Assignee
Julian LadischJulian LadischReporter
Julian LadischJulian LadischPriority
P2Development Team
Core: PlatformFix versions
Release
Poppy (R2 2023) Bug FixRCA Group
Related dependency upgradeTestRail: Cases
Open TestRail: CasesTestRail: Runs
Open TestRail: Runs
Details
Details
Assignee
Julian Ladisch
Julian LadischReporter
Julian Ladisch
Julian LadischPriority
Development Team
Core: Platform
Fix versions
Release
Poppy (R2 2023) Bug Fix
RCA Group
Related dependency upgrade
TestRail: Cases
Open TestRail: Cases
TestRail: Runs
Open TestRail: Runs
Created November 1, 2023 at 9:06 PM
Updated November 7, 2023 at 9:50 PM
Resolved November 7, 2023 at 9:48 PM
Upgrade Vert.x from 4.4.5 to 4.4.6. This indirectly upgrades Netty from 4.1.97.Final to 4.1.100.Final fixing Denial of Service (DoS): https://nvd.nist.gov/vuln/detail/CVE-2023-44487
Upgrade Okapi from 5.0.2 to 5.1.2 to match the Vert.x version.
Upgrade Testcontainers from 1.19.0 to 1.19.1. This indirectly upgrades commons-compress from 1.23.0 to 1.24.0 fixing Improper Input Validation: https://nvd.nist.gov/vuln/detail/CVE-2023-42503