Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

address CVE-2019-13990 by updating quartz from 2.2.3 to 2.3.2 #117

Merged
merged 1 commit into from
Feb 20, 2024

Conversation

mluckam
Copy link

@mluckam mluckam commented Feb 27, 2023

The latest version of the grails quartz plugin, currently 2.0.13, has the vulnerability CVE-2019-13990. This issue is addressed by updating to quartz 2.3.2. Instead of users updating the dependency themselves, see example, this issue should be addressed in the plugin directly. Relevant links:
quartz github issue
maven central vulnerability

@mluckam
Copy link
Author

mluckam commented Mar 8, 2023

This repository has been inactive for a few years. @puneetbehl it appears you are the latest maintainer. Mind taking a look?

@mluckam
Copy link
Author

mluckam commented Apr 13, 2023

@puneetbehl are you able to take a look at this or refer me to another maintainer of the project?

1 similar comment
@mluckam
Copy link
Author

mluckam commented May 11, 2023

@puneetbehl are you able to take a look at this or refer me to another maintainer of the project?

@mluckam
Copy link
Author

mluckam commented Feb 13, 2024

@Richardson-e @mattmoss @puneetbehl are you able to take a look at this?

@puneetbehl
Copy link
Contributor

Sorry for the delayed response. Thank you for this PR. We are working on updating a new version of the Quatz plugin and wiil include all these changes. @Richardson-e Could you please add these changes to the latest codebase.

@puneetbehl puneetbehl merged commit 70b29de into grails:master Feb 20, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants