Skip to content

Commit

Permalink
upgrade dropwizard and jetty to resolve security issue
Browse files Browse the repository at this point in the history
  • Loading branch information
akphi committed Oct 26, 2020
1 parent ad9d0da commit 0b3b57e
Showing 1 changed file with 12 additions and 1 deletion.
13 changes: 12 additions & 1 deletion pom.xml
Original file line number Diff line number Diff line change
Expand Up @@ -44,7 +44,7 @@

<!-- Dependencies -->
<commons.lang.version>2.6</commons.lang.version>
<dropwizard.version>1.3.24</dropwizard.version>
<dropwizard.version>1.3.26</dropwizard.version>
<dropwizard.pac4j.version>3.0.0</dropwizard.pac4j.version>
<guava.version>28.1-jre</guava.version>
<jackson.annotations.version>2.10.1</jackson.annotations.version>
Expand All @@ -57,6 +57,7 @@
<jaxb.runtime.version>2.3.2</jaxb.runtime.version>
<jersey.client.version>2.23.2</jersey.client.version>
<jersey.test.framework.version>2.23.1</jersey.test.framework.version>
<jetty.version>9.4.33.v20201020</jetty.version>
<joda.time.version>2.10.1</joda.time.version>
<junit.version>4.13.1</junit.version>
<slf4j.version>1.7.21</slf4j.version>
Expand Down Expand Up @@ -518,6 +519,16 @@
</dependency>
<!-- Jersey -->

<!-- Jetty -->
<!-- The following Jetty dependencies are added to address security issues, this can be removed once we upgrade dropwizard -->
<!-- See https://nvd.nist.gov/vuln/detail/CVE-2020-27216 -->
<dependency>
<groupId>org.eclipse.jetty</groupId>
<artifactId>jetty-webapp</artifactId>
<version>${jetty.version}</version>
</dependency>
<!-- Jetty -->

<!-- Mongo -->
<dependency>
<groupId>org.mongodb</groupId>
Expand Down

0 comments on commit 0b3b57e

Please sign in to comment.