Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Fixed Veracode security CVE-2023-46589 and CVE-2023-34053 #81

Merged

Conversation

amoldashwant
Copy link
Contributor

Description

  • Fixed Veracode security CVE-2023-46589(tomcat-embed-core) and CVE-2023-34053(spring-web):
    Excluded tomcat-embed-core and newer version
    reason: org.apache.tomcat: tomcat-catalina(10.1.18) is vulnerable to Request Smuggling

Excluded spring-web old versions and added newer version
reason: org.springframework: spring-web (6.0.9) is vulnerable to Denial Of Service (DoS)

Pre-review checks

Please ensure to do as many of the following checks as possible, before asking for committer review:

Copy link
Contributor

@sachinargade123 sachinargade123 left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@amoldashwant @adityagajbhiye9 Please update change log file as per changes

@amoldashwant
Copy link
Contributor Author

@sachinargade123 @dvasunin
please review

Copy link
Contributor

@dvasunin dvasunin left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

Copy link
Contributor

@sachinargade123 sachinargade123 left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@adityagajbhiye9
Copy link
Contributor

@almadigabor Please review and merge.

Copy link
Contributor

@almadigabor almadigabor left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@almadigabor almadigabor merged commit 75307a6 into eclipse-tractusx:main Dec 5, 2023
3 checks passed
@almadigabor almadigabor deleted the veracode_security_fix_23-46589 branch December 5, 2023 09:42
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

5 participants