-
Notifications
You must be signed in to change notification settings - Fork 5.9k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Address CVE-2023-1370 #13146
Address CVE-2023-1370 #13146
Conversation
Bump oauth2-oidc-sdk to 10.7.1 to update json-smart to 2.4.10
@fredbalves86 Please sign the Contributor License Agreement! Click here to manually synchronize the status of this Pull Request. See the FAQ for frequently asked questions. |
@fredbalves86 Thank you for signing the Contributor License Agreement! |
Thanks for the PR, @fredbalves86. Since |
I've logged an issue to see what response we get. |
Change oauth2-oidc-sdk to 9.43.2
They've released the new version 9.43.2. Updated the PR with the new commit |
Change oauth2-oidc-sdk to 9.43.2
…redbalves86/spring-security into bump_oauth2-oidc-sdk_to_10.7.1
Thanks, @fredbalves86! This is now merged into |
Bump oauth2-oidc-sdk to 10.7.1 to update json-smart to 2.4.10
oauth2-oidc-sdk:9.43.1
usesjson-smart-2.4.8
which is vulnerable to the following CVE-2023-1370Updated the version to
10.7.1
to usejson-smart-2.4.10
to fix the vulnerability