Uploaded image for project: 'Karaf'
  1. Karaf
  2. KARAF-7710

Fix CVE-2023-33201 in BouncyCastle

    XMLWordPrintableJSON

Details

    • Bug
    • Status: Resolved
    • Major
    • Resolution: Fixed
    • 4.4.3
    • 4.4.4, 4.3.10
    • karaf
    • None

    Description

      Karaf 4.4.3 uses BouncyCastle 1.70 which is vulnerable to CVE-2023-33201.

      I'll submit a PR to update to 1.75, which also involves changing the maven groupid from jdk15on to jdk18on.

      Attachments

        Activity

          People

            jbonofre Jean-Baptiste Onofré
            coheigea Colm O hEigeartaigh
            Votes:
            0 Vote for this issue
            Watchers:
            3 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: