Movatterモバイル変換


[0]ホーム

URL:


Skip to content

Navigation Menu

Sign in
Appearance settings

Search code, repositories, users, issues, pull requests...

Provide feedback

We read every piece of feedback, and take your input very seriously.

Saved searches

Use saved searches to filter your results more quickly

Sign up
Appearance settings

Upgrade utils-mail-smime dependency to 2.3.2, to resolve CVE issue in bouncycastle#506

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to ourterms of service andprivacy statement. We’ll occasionally send you account related emails.

Already on GitHub?Sign in to your account

Merged
bbottema merged 1 commit intobbottema:masterfromrover886:patch-1
Apr 23, 2024

Conversation

@rover886
Copy link
Contributor

latest version of the smime-module should refer to utils-mail-smime version 2.3.2.

latest version of the smime-module should refer to utils-mail-smime version 2.3.2.
@rover886
Copy link
ContributorAuthor

Hi@bbottema we received an snyk report mentioning

✗ Observable Timing Discrepancy [Medium Severity][https://security.snyk.io/vuln/SNYK-JAVA-ORGBOUNCYCASTLE-6277382] in org.bouncycastle:bcprov-jdk15to18@1.75introduced by org.simplejavamail:smime-module@8.1.3 > org.simplejavamail:utils-mail-smime@2.1.2 > org.bouncycastle:bcjmail-jdk15to18@1.75 > org.bouncycastle:bcprov-jdk15to18@1.75 and 2 other path(s

To resolve this we updated smime-module to 8.8.3 but it still not resolved the issue, because 8.8.3 is still referring to utils-mail-smime version 2.3.1 which again refers to version 1.75 of BC. Hence this PR is to bump up the version of utils-mail-smime to 2.3.2 which is latest and which refers to 1.78 version of BC.

@bbottemabbottema merged commite6e4d19 intobbottema:masterApr 23, 2024
@bbottema
Copy link
Owner

bbottema commentedApr 23, 2024
edited
Loading

I'm in the process of updating a lot of 3rd party dependencies, to solve all transitive known CVE issues. However, I can release a patch version for you in the meantime.

rover886 reacted with thumbs up emoji

@bbottemabbottema changed the titleUpdate pom.xmlUpgrade utils-mail-smime dependency to 2.3.2, to resolve CVE issue in bouncycastleApr 23, 2024
@bbottemabbottema added this to the8.8.4 milestoneApr 23, 2024
@bbottema
Copy link
Owner

Released in 8.8.4.

@rover886
Copy link
ContributorAuthor

Tons of thanks@bbottema for taking this effort to release a new version with lighting fast speed.

@bbottema
Copy link
Owner

I just released 8.9.0, see detailshere.

Sign up for freeto join this conversation on GitHub. Already have an account?Sign in to comment

Reviewers

No reviews

Assignees

No one assigned

Projects

None yet

Milestone

8.8.4

Development

Successfully merging this pull request may close these issues.

2 participants

@rover886@bbottema

[8]ページ先頭

©2009-2025 Movatter.jp