<!-- 
RSS generated by JIRA (1001.0.0-SNAPSHOT#100246-sha1:7a5c50119eb0633d306e14180817ddef5e80c75d) at Thu Feb 08 23:29:55 UTC 2024

It is possible to restrict the fields that are returned in this document by specifying the 'field' parameter in your request.
For example, to request only the issue key and summary add field=key&field=summary to the URL of your request.
-->
<rss version="0.92" >
<channel>
    <title>FOLIO Jira</title>
    <link>https://folio-org.atlassian.net</link>
    <description>This file is an XML representation of an issue</description>
    <language>en-us</language>    <build-info>
        <version>1001.0.0-SNAPSHOT</version>
        <build-number>100246</build-number>
        <build-date>07-02-2024</build-date>
    </build-info>

<item>
            <title>[FOLIO-3682] Rebuild folioci/alpine-jre-openjdk11 and folioci/alpine-jre-openjdk17</title>
                <link>https://folio-org.atlassian.net/browse/FOLIO-3682</link>
                <project id="10290" key="FOLIO">FOLIO</project>
                    <description>&lt;p&gt;These are the base Docker containers to support Java-based back-end FOLIO modules.&lt;/p&gt;

&lt;p&gt;Rebuild folio-tools/folio-java-docker/openjdk11 and folio-tools/folio-java-docker/openjdk17&lt;/p&gt;

&lt;p&gt;folioci/alpine-jre-openjdk11:latest = 1.3.9 and folioci/alpine-jre-openjdk17:latest = 2.0.6 ship with the OpenSSL libraries libcrypto3 3.0.7-r2 and libssl3 3.0.7-r2, example for 11 and libssl3:&lt;/p&gt;
&lt;div class=&quot;code panel&quot; style=&quot;border-width: 1px;&quot;&gt;&lt;div class=&quot;codeContent panelContent&quot;&gt;
&lt;pre class=&quot;code-java&quot;&gt;
docker run --rm -it --entrypoint /sbin/apk folioci/alpine-jre-openjdk11:latest list libssl3
libssl3-3.0.7-r2 x86_64 {openssl} (Apache-2.0) [installed]
&lt;/pre&gt;
&lt;/div&gt;&lt;/div&gt;
&lt;p&gt;They have these OpenSSL vulnerabilities:&lt;/p&gt;
&lt;ul&gt;
	&lt;li&gt;7.5 HIGH &lt;a href=&quot;https://nvd.nist.gov/vuln/detail/CVE-2023-0401&quot; class=&quot;external-link&quot; rel=&quot;nofollow noreferrer&quot;&gt;https://nvd.nist.gov/vuln/detail/CVE-2023-0401&lt;/a&gt;&lt;/li&gt;
	&lt;li&gt;7.4 HIGH &lt;a href=&quot;https://nvd.nist.gov/vuln/detail/CVE-2023-0286&quot; class=&quot;external-link&quot; rel=&quot;nofollow noreferrer&quot;&gt;https://nvd.nist.gov/vuln/detail/CVE-2023-0286&lt;/a&gt;&lt;/li&gt;
	&lt;li&gt;7.5 HIGH &lt;a href=&quot;https://nvd.nist.gov/vuln/detail/CVE-2023-0217&quot; class=&quot;external-link&quot; rel=&quot;nofollow noreferrer&quot;&gt;https://nvd.nist.gov/vuln/detail/CVE-2023-0217&lt;/a&gt;&lt;/li&gt;
	&lt;li&gt;7.5 HIGH &lt;a href=&quot;https://nvd.nist.gov/vuln/detail/CVE-2023-0216&quot; class=&quot;external-link&quot; rel=&quot;nofollow noreferrer&quot;&gt;https://nvd.nist.gov/vuln/detail/CVE-2023-0216&lt;/a&gt;&lt;/li&gt;
	&lt;li&gt;7.5 HIGH &lt;a href=&quot;https://nvd.nist.gov/vuln/detail/CVE-2023-0215&quot; class=&quot;external-link&quot; rel=&quot;nofollow noreferrer&quot;&gt;https://nvd.nist.gov/vuln/detail/CVE-2023-0215&lt;/a&gt;&lt;/li&gt;
	&lt;li&gt;7.5 HIGH &lt;a href=&quot;https://nvd.nist.gov/vuln/detail/CVE-2022-4450&quot; class=&quot;external-link&quot; rel=&quot;nofollow noreferrer&quot;&gt;https://nvd.nist.gov/vuln/detail/CVE-2022-4450&lt;/a&gt;&lt;/li&gt;
	&lt;li&gt;5.9 MEDIUM &lt;a href=&quot;https://nvd.nist.gov/vuln/detail/CVE-2022-4304&quot; class=&quot;external-link&quot; rel=&quot;nofollow noreferrer&quot;&gt;https://nvd.nist.gov/vuln/detail/CVE-2022-4304&lt;/a&gt;&lt;/li&gt;
	&lt;li&gt;N/A &lt;a href=&quot;https://nvd.nist.gov/vuln/detail/CVE-2022-4203&quot; class=&quot;external-link&quot; rel=&quot;nofollow noreferrer&quot;&gt;https://nvd.nist.gov/vuln/detail/CVE-2022-4203&lt;/a&gt;&lt;/li&gt;
	&lt;li&gt;7.5 HIGH &lt;a href=&quot;https://nvd.nist.gov/vuln/detail/CVE-2022-3996&quot; class=&quot;external-link&quot; rel=&quot;nofollow noreferrer&quot;&gt;https://nvd.nist.gov/vuln/detail/CVE-2022-3996&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;


&lt;p&gt;As the Dockerfile already contains &quot;apk upgrade&quot; a rebuild of the container will automatically upgrade libssl3 and librcypto3 to the fixed version 3.0.8-r0.&lt;/p&gt;</description>
                <environment></environment>
        <key id="82475">FOLIO-3682</key>
            <summary>Rebuild folioci/alpine-jre-openjdk11 and folioci/alpine-jre-openjdk17</summary>
                <type id="10003" iconUrl="https://folio-org.atlassian.net/rest/api/2/universal_avatar/view/type/issuetype/avatar/10318?size=medium">Task</type>
                                            <priority id="10005" iconUrl="https://dev.folio.org/assets/jira-priority/tbd.svg">TBD</priority>
                        <status id="6" iconUrl="https://folio-org.atlassian.net/images/icons/statuses/closed.png" description="The issue is considered finished, the resolution is correct. Issues which are closed can be reopened.">Closed</status>
                    <statusCategory id="3" key="done" colorName="green"/>
                                    <resolution id="10003">Done</resolution>
                                                        <assignee accountid="61cd0ca0bce5e00069e98be7">David Crossley</assignee>
                                                                <reporter accountid="61cd0ca0bce5e00069e98be7">David Crossley</reporter>
                                    <labels>
                            <label>security</label>
                    </labels>
                <created>Thu, 5 Jan 2023 23:34:39 +0000</created>
                <updated>Fri, 3 Mar 2023 01:19:35 +0000</updated>
                            <resolved>Fri, 3 Mar 2023 01:19:35 +0000</resolved>
                                                                        <due></due>
                            <votes>0</votes>
                                    <watches>1</watches>
                                                                <comments>
                                                            <comment id="198449" author="61cd0ca0bce5e00069e98be7" created="Fri, 3 Mar 2023 01:19:21 +0000"  >&lt;p&gt;Built on jenkins host and pushed as &quot;alpine-jre-openjdk17:2.0.7&quot; and &quot;latest&quot;.&lt;br/&gt;
Built on jenkins host and pushed as &quot;alpine-jre-openjdk11:1.3.10&quot; and &quot;latest&quot;.&lt;/p&gt;</comment>
                    </comments>
                    <attachments>
                    </attachments>
                <subtasks>
                    </subtasks>
                <customfields>
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                <customfield id="customfield_10000" key="com.atlassian.jira.plugins.jira-development-integration-plugin:devsummarycf">
                        <customfieldname>Development</customfieldname>
                        <customfieldvalues>
                            
                        </customfieldvalues>
                    </customfield>
                                                                <customfield id="customfield_10057" key="com.atlassian.jira.plugin.system.customfieldtypes:select">
                        <customfieldname>Development Team</customfieldname>
                        <customfieldvalues>
                                <customfieldvalue key="10155"><![CDATA[FOLIO DevOps]]></customfieldvalue>

                        </customfieldvalues>
                    </customfield>
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                <customfield id="customfield_10063" key="com.atlassian.jira.plugin.system.customfieldtypes:float">
                        <customfieldname>PO Rank</customfieldname>
                        <customfieldvalues>
                            <customfieldvalue>0.0</customfieldvalue>
                        </customfieldvalues>
                    </customfield>
                                                                                                                                                                                                                                                                    <customfield id="customfield_10106" key="com.atlassian.jira.plugin.system.customfieldtypes:select">
                        <customfieldname>RCA Group</customfieldname>
                        <customfieldvalues>
                                <customfieldvalue key="10385"><![CDATA[Related dependency upgrade]]></customfieldvalue>

                        </customfieldvalues>
                    </customfield>
                                                                                            <customfield id="customfield_10019" key="com.pyxis.greenhopper.jira:gh-lexo-rank">
                        <customfieldname>Rank</customfieldname>
                        <customfieldvalues>
                            <customfieldvalue>0|i062k8:</customfieldvalue>

                        </customfieldvalues>
                    </customfield>
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    <customfield id="customfield_10020" key="com.pyxis.greenhopper.jira:gh-sprint">
                        <customfieldname>Sprint</customfieldname>
                        <customfieldvalues>
                                <customfieldvalue id="2016">DevOps Sprint 159</customfieldvalue>
    <customfieldvalue id="1718">DevOps Sprint 160</customfieldvalue>

                        </customfieldvalues>
                    </customfield>
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    <customfield id="customfield_10025" key="com.atlassian.jira.ext.charting:timeinstatus">
                        <customfieldname>[CHART] Time in Status</customfieldname>
                        <customfieldvalues>
                            
                        </customfieldvalues>
                    </customfield>
                                    </customfields>
    </item>
</channel>
</rss>