Skip to content

Commit

Permalink
Update Bouncycastle to 1.78.1 for CVE-2023-33201 (#5804)
Browse files Browse the repository at this point in the history
Resolves #5780
  • Loading branch information
onobc authored May 9, 2024
1 parent 594dcb4 commit 3b9cf4e
Show file tree
Hide file tree
Showing 2 changed files with 39 additions and 1 deletion.
Original file line number Diff line number Diff line change
Expand Up @@ -30,6 +30,7 @@
<testcontainers.version>1.19.7</testcontainers.version>
<!-- Specific version overrides to deal w/ CVEs -->
<tomcat.version>9.0.88</tomcat.version>
<bouncycastle.version>1.78.1</bouncycastle.version>
<spring-kafka.version>2.9.13</spring-kafka.version>
<netty.version>4.1.109.Final</netty.version>
<reactor-bom.version>2020.0.43</reactor-bom.version>
Expand Down Expand Up @@ -190,6 +191,22 @@
<artifactId>spring-cloud-services-starter-config-client</artifactId>
<version>${spring-cloud-services-starter-config-client.version}</version>
</dependency>
<!-- Provide Bouncycastle dep. mgmt. -->
<dependency>
<groupId>org.bouncycastle</groupId>
<artifactId>bcprov-jdk18on</artifactId>
<version>${bouncycastle.version}</version>
</dependency>
<dependency>
<groupId>org.bouncycastle</groupId>
<artifactId>bcpkix-jdk18on</artifactId>
<version>${bouncycastle.version}</version>
</dependency>
<dependency>
<groupId>org.bouncycastle</groupId>
<artifactId>bcutil-jdk18on</artifactId>
<version>${bouncycastle.version}</version>
</dependency>
</dependencies>
</dependencyManagement>
<profiles>
Expand Down
23 changes: 22 additions & 1 deletion spring-cloud-dataflow-parent/pom.xml
Original file line number Diff line number Diff line change
Expand Up @@ -34,6 +34,7 @@
<jettison.version>1.5.4</jettison.version>
<!-- Specific version overrides to deal w/ CVEs -->
<tomcat.version>9.0.88</tomcat.version>
<bouncycastle.version>1.78.1</bouncycastle.version>
<spring-kafka.version>2.9.13</spring-kafka.version>
<netty.version>4.1.109.Final</netty.version>
<reactor-bom.version>2020.0.43</reactor-bom.version>
Expand Down Expand Up @@ -142,7 +143,7 @@
<artifactId>logback-access</artifactId>
<version>${logback.version}</version>
</dependency>
<!-- There is no embedded tomcat BOM unfortunately -->
<!-- Override embedded Tomcat provided by Spring Boot (no BOM unfortunately) -->
<dependency>
<groupId>org.apache.tomcat.embed</groupId>
<artifactId>tomcat-embed-core</artifactId>
Expand All @@ -168,27 +169,47 @@
<artifactId>spring-kafka</artifactId>
<version>${spring-kafka.version}</version>
</dependency>
<!-- Override Netty provided by Spring Boot -->
<dependency>
<groupId>io.netty</groupId>
<artifactId>netty-bom</artifactId>
<version>${netty.version}</version>
<type>pom</type>
<scope>import</scope>
</dependency>
<!-- Override Reactor provided by Spring Boot -->
<dependency>
<groupId>io.projectreactor</groupId>
<artifactId>reactor-bom</artifactId>
<version>${reactor-bom.version}</version>
<type>pom</type>
<scope>import</scope>
</dependency>
<!-- Override RSocket provided by Spring Boot -->
<dependency>
<groupId>io.rsocket</groupId>
<artifactId>rsocket-bom</artifactId>
<version>${rsocket.version}</version>
<type>pom</type>
<scope>import</scope>
</dependency>
<!-- Provide Bouncycastle dep. mgmt. -->
<dependency>
<groupId>org.bouncycastle</groupId>
<artifactId>bcprov-jdk18on</artifactId>
<version>${bouncycastle.version}</version>
</dependency>
<dependency>
<groupId>org.bouncycastle</groupId>
<artifactId>bcpkix-jdk18on</artifactId>
<version>${bouncycastle.version}</version>
</dependency>
<dependency>
<groupId>org.bouncycastle</groupId>
<artifactId>bcutil-jdk18on</artifactId>
<version>${bouncycastle.version}</version>
</dependency>
<!-- Override dependencies should go above this comment -->
<dependency>
<groupId>org.springframework</groupId>
<artifactId>spring-framework-bom</artifactId>
Expand Down

0 comments on commit 3b9cf4e

Please sign in to comment.